SmartCrawl < 3.16.3 - Subscriber+ Private/Draft Post Title Disclosure and Post Meta Key Enumeration
Summary
| CVE | CVE-2026-16979 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-19 06:17:36 UTC |
| Updated | 2026-08-19 06:17:36 UTC |
| Description | The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability checks on two of its AJAX actions, allowing users with at least the Subscriber role to read the titles of private and draft posts by ID and to enumerate stored post-meta key names. |
Risk And Classification
Problem Types: CWE-639 Authorization Bypass Through User-Controlled Key
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Unknown | SmartCrawl SEO Checker Analyzer Optimizer | affected 3.16.3 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/c9eb27aa-c5f9-4f1c-b87c-337ebaf192dd | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Ezekiel Victor (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.