CVE Database /
CVE-2024-6556
CVE · Medium
CVE-2024-6556 — SmartCrawl SEO checker, analyzer & optimizer [smartcrawl-seo] < 3.10.9
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-6556
|
SmartCrawl SEO checker, analyzer & optimizer [smartcrawl-seo] < 3.10.9 |
Exposure of Sensitive Information to an Unauthorized Actor |
Medium
5.3
|
< 3.10.9
|
3.10.9 |
2024-07-09 |
—
|
CVE-2024-6556
A security flaw exists in SmartCrawl WordPress SEO plugin versions prior to 3.10.8, allowing unauthorized individuals to uncover the full web application path through direct file access. This occurs because mobiledetect is used without adequate protection measures, enabling attackers to exploit this weakness. While the exposed information alone poses no threat, it can be leveraged in conjunction with other vulnerabilities to compromise a website's security.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings