{"api_version":"1","generated_at":"2026-08-19T11:43:50+00:00","cve":"CVE-2026-16979","urls":{"html":"https://cve.report/CVE-2026-16979","api":"https://cve.report/api/cve/CVE-2026-16979.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-16979","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-16979"},"summary":{"title":"SmartCrawl < 3.16.3 - Subscriber+ Private/Draft Post Title Disclosure and Post Meta Key Enumeration","description":"The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability checks on two of its AJAX actions, allowing users with at least the Subscriber role to read the titles of private and draft posts by ID and to enumerate stored post-meta key names.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-08-19 06:17:36","updated_at":"2026-08-19 06:17:36"},"problem_types":["CWE-639 Authorization Bypass Through User-Controlled Key"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/c9eb27aa-c5f9-4f1c-b87c-337ebaf192dd/","name":"https://wpscan.com/vulnerability/c9eb27aa-c5f9-4f1c-b87c-337ebaf192dd/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-16979","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16979","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"SmartCrawl SEO checker, analyzer & optimizer","version":"affected 3.16.3 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Ezekiel Victor","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"SmartCrawl SEO checker, analyzer & optimizer","vendor":"Unknown","versions":[{"lessThan":"3.16.3","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Ezekiel Victor"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability checks on two of its AJAX actions, allowing users with at least the Subscriber role to read the titles of private and draft posts by ID and to enumerate stored post-meta key names."}],"problemTypes":[{"descriptions":[{"description":"CWE-639 Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-19T06:00:17.806Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/c9eb27aa-c5f9-4f1c-b87c-337ebaf192dd/"}],"source":{"discovery":"EXTERNAL"},"title":"SmartCrawl < 3.16.3 - Subscriber+ Private/Draft Post Title Disclosure and Post Meta Key Enumeration","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-16979","datePublished":"2026-08-19T06:00:17.806Z","dateReserved":"2026-07-24T08:34:55.539Z","dateUpdated":"2026-08-19T06:00:17.806Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-19 06:17:36","lastModifiedDate":"2026-08-19 06:17:36","problem_types":["CWE-639 Authorization Bypass Through User-Controlled Key"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"16979","Ordinal":"1","Title":"SmartCrawl < 3.16.3 - Subscriber+ Private/Draft Post Title Discl","CVE":"CVE-2026-16979","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"16979","Ordinal":"1","NoteData":"The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability checks on two of its AJAX actions, allowing users with at least the Subscriber role to read the titles of private and draft posts by ID and to enumerate stored post-meta key names.","Type":"Description","Title":"SmartCrawl < 3.16.3 - Subscriber+ Private/Draft Post Title Discl"}]}}}