Loading market data...
← Back to CVE feed

CVE-2026-16979

MEDIUM CVSS 4.3 View on NVD ↗

Description

The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability checks on two of its AJAX actions, allowing users with at least the Subscriber role to read the titles of private and draft posts by ID and to enumerate stored post-meta key names.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Published: Aug 19, 2026 06:17 UTC Modified: Aug 19, 2026 18:16 UTC