CVE · Medium

CVE-2026-59520 — CrawlWP SEO – Instant Search Engine Indexing & SEO Performance Monitor [mihdan-index-now] < 3.0.17

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-59520 CrawlWP SEO – Instant Search Engine Indexing & SEO Performance Monitor [mihdan-index-now] < 3.0.17 Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.0.17 3.0.17 2026-07-05

CVE-2026-59520

The CrawlWP SEO plugin, used in WordPress installations up to version 3.0.16, contains a security flaw that allows malicious actors to execute unauthorized actions without needing authentication. This vulnerability arises from inadequate validation of nonces within the plugin's functionality. As a result, an attacker can potentially deceive a site administrator into performing certain actions by tricking them into clicking on a specially crafted link.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.