← WordPress Vulnerabilities
WordPress security by component

Improve SEO

Improve SEO (improve-seo) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 04, 2026; the highest published CVSS base score is 9.8.

Plugin slug: improve-seo

CVE-2026-16618: Improve SEO permits unauthenticated executable PHP uploads

Improve SEO through 2.0.11 validates an uploaded file's reported content type but preserves the attacker-supplied extension when writing it into a publicly accessible directory. An unauthenticated attacker can therefore upload a PHP file and request the resulting public URL to execute code on the server. The public advisory withholds its proof of concept and does not disclose the upload endpoint, field name, destination path or URL pattern.

PublishedAug 04, 2026
Known safe version> 2.0.11
Published vulnerabilities for improve-seo
Safe version
Aug 04, 2026 CVE-2026-16618
Improve SEO permits unauthenticated executable PHP uploads
Improve SEO through 2.0.11 validates an uploaded file's reported content type but preserves the attacker-supplied extension when writing it into a publicly accessible directory. An unauthenticated attacker can therefore upload a PHP file and request the resulting public URL to execute code on the server. The public advisory withholds its proof of concept and does not disclose the upload endpoint, field name, destination path or URL pattern.
> 2.0.11
CVE9.8
NVDPending