CVE-2026-16979

The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability checks on two of its AJAX actions, allowing users with at least the Subscriber role to read the titles of private and draft posts by ID and to enumerate stored post-meta key names.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-19 06:17

Updated : 2026-08-26 16:30


NVD link : CVE-2026-16979

Mitre link : CVE-2026-16979

CVE.ORG link : CVE-2026-16979


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key