Description
The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability checks on two of its AJAX actions, allowing users with at least the Subscriber role to read the titles of private and draft posts by ID and to enumerate stored post-meta key names.
Published: 2026-08-19
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before version 3.16.3 fails to verify user capabilities for two AJAX actions. As a result, any authenticated user with the Subscriber role or higher can request the titles of private or draft posts by ID and can list the names of stored post‑meta keys, revealing information that should remain confidential.

Affected Systems

This vulnerability affects the SmartCrawl SEO checker, analyzer & optimizer WordPress plugin of unknown vendor for all releases earlier than 3.16.3. The plugin must be upgraded to 3.16.3 or later to eliminate the flaw.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. It is not listed in the CISA KEV catalog, meaning no widespread exploitation has been documented. The attack surface is limited to authenticated users who can reach the plugin’s AJAX endpoints, typically via standard HTTP requests. An attacker with a Subscriber account can gain insight into unpublished content and the structure of post meta, which could aid in planning further attacks against the site.

Generated by OpenCVE AI on August 20, 2026 at 12:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest SmartCrawl SEO checker, analyzer & optimizer WordPress plugin update (3.16.3 or later).
  • Restrict Subscriber and lower role user access, or remove the Subscriber role from user accounts that do not need it.
  • If the plugin is not required, uninstall it or block its AJAX endpoints using firewall rules to limit external access.

Generated by OpenCVE AI on August 20, 2026 at 12:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Wed, 19 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability checks on two of its AJAX actions, allowing users with at least the Subscriber role to read the titles of private and draft posts by ID and to enumerate stored post-meta key names.
Title SmartCrawl < 3.16.3 - Subscriber+ Private/Draft Post Title Disclosure and Post Meta Key Enumeration
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-19T18:08:30.359Z

Reserved: 2026-07-24T08:34:55.539Z

Link: CVE-2026-16979

cve-icon Vulnrichment

Updated: 2026-08-19T18:08:18.423Z

cve-icon NVD

Status : Deferred

Published: 2026-08-19T06:17:36.013

Modified: 2026-08-26T16:30:52.723

Link: CVE-2026-16979

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T13:00:13Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key