CVE-2026-16979
SmartCrawl < 3.16.3 - Subscriber+ Private/Draft Post Title Disclosure and Post Meta Key Enumeration
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability checks on two of its AJAX actions, allowing users with at least the Subscriber role to read the titles of private and draft posts by ID and to enumerate stored post-meta key names.
| Vendor | unknown |
| Product | smartcrawl seo checker, analyzer & optimizer |
| Published | Aug 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown smartcrawl seo checker, analyzer & optimizer
Be the first to know when new unknown vulnerabilities affecting unknown smartcrawl seo checker, analyzer & optimizer are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / SmartCrawl SEO checker, analyzer & optimizer
0 < 3.16.3
References
Credits
Ezekiel Victor WPScan