WordPress security by component
Improve SEO
Improve SEO (improve-seo) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 04, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
improve-seoLatest vulnerability
CVE-2026-16618: Improve SEO permits unauthenticated executable PHP uploads
Improve SEO through 2.0.11 validates an uploaded file's reported content type but preserves the attacker-supplied extension when writing it into a publicly accessible directory. An unauthenticated attacker can therefore upload a PHP file and request the resulting public URL to execute code on the server. The public advisory withholds its proof of concept and does not disclose the upload endpoint, field name, destination path or URL pattern.
| Safe version |
|
||
|---|---|---|---|
| Aug 04, 2026 |
CVE-2026-16618
Improve SEO permits unauthenticated executable PHP uploads
Improve SEO through 2.0.11 validates an uploaded file's reported content type but preserves the attacker-supplied extension when writing it into a publicly accessible directory. An unauthenticated attacker can therefore upload a PHP file and request the resulting public URL to execute code on the server. The public advisory withholds its proof of concept and does not disclose the upload endpoint, field name, destination path or URL pattern.
|
> 2.0.11 |
CVE9.8
NVDPending
|