CVE-2026-16979
MEDIUM 4.3EPSS 0.2%
The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability checks on two of its AJAX actions, allowing users with at least the Subscriber role to read the titles of private and draft posts by ID and to enumerate stored post-meta key names.
- CVSS v3.1
- 4.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N - EPSS
- 0.20% chance of exploitation in the next 30 days, 9th percentile
- Published
- 2026-08-19