CVE-2024-3287: SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer <= 3.10.2 - Missing Authorization
The SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer plugin for WordPress is vulnerable to unauthorized ld+json description injection due to a missing capability check on the savesettings function in all versions up to, and including, 3.10.2. This makes it possible for unauthenticated attackers to save schema types.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3287?
CVE-2024-3287 is considered a high severity vulnerability due to its potential for unauthorized JSON description injection.
How do I fix CVE-2024-3287?
To fix CVE-2024-3287, update the SmartCrawl WordPress SEO plugin to version 3.10.3 or later, which includes the necessary security patches.
Who is affected by CVE-2024-3287?
All versions of the SmartCrawl WordPress SEO plugin up to and including 3.10.2 are vulnerable to CVE-2024-3287.
What type of attacks can exploit CVE-2024-3287?
CVE-2024-3287 can be exploited via unauthorized injection of ld+json descriptions, allowing for potential manipulation of site content.
Is there a workaround for CVE-2024-3287 if I can't update immediately?
A temporary workaround for CVE-2024-3287 includes disabling the SmartCrawl plugin until an update can be applied.