CVE-2026-16979: Unknown Smartcrawl Seo Checker, Analyzer & Optimizer

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability checks on two of its AJAX actions, allowing users with at least the Subscriber role to read the titles of private and draft posts by ID and to enumerate stored post-meta key names.

Affected products

  • Unknown Smartcrawl Seo Checker, Analyzer & Optimizer: before 3.16.3 (fixed in 3.16.3)

Published 2026-08-19. Last modified 2026-08-26.