PT-2025-39960 · WordPress · Smartcrawl Seo

Rafshanzani Suhada

·

Published

2025-09-30

·

Updated

2025-09-30

·

CVE-2025-11163

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions SmartCrawl SEO plugin for WordPress versions prior to 3.14.4
Description The SmartCrawl SEO plugin for WordPress has an issue where data can be modified without authorization. This is due to a missing capability check within the update submodule() function. Authenticated attackers with Subscriber-level access or higher can update the plugin’s settings.
Recommendations Update the SmartCrawl SEO plugin to version 3.14.4 or later.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-11163

Affected Products

Smartcrawl Seo