Security Advisory

CVE-2026-16979

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-19 06:00:17
Last updated 2026-08-19 18:08:30
Assigner WPScan
CVSS score 4.3
State PUBLISHED

Description

The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability checks on two of its AJAX actions, allowing users with at least the Subscriber role to read the titles of private and draft posts by ID and to enumerate stored post-meta key names.