CVE-2025-11163: SmartCrawl SEO checker, analyzer & optimizer <= 3.14.3 - Missing Authorization to Plugin Settings Update
The SmartCrawl SEO checker, analyzer & optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the updatesubmodule() function in all versions up to, and including, 3.14.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's setttings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11163?
CVE-2025-11163 is classified as a critical vulnerability due to its potential for unauthorized data modification by authenticated users.
How do I fix CVE-2025-11163?
To fix CVE-2025-11163, update the SmartCrawl SEO checker, analyzer & optimizer plugin to version 3.14.4 or later.
What versions are affected by CVE-2025-11163?
CVE-2025-11163 affects all versions of the SmartCrawl SEO checker, analyzer & optimizer plugin up to and including version 3.14.3.
Who can exploit CVE-2025-11163?
CVE-2025-11163 can be exploited by authenticated users who can access the vulnerable function without proper capability checks.
What does CVE-2025-11163 impact?
CVE-2025-11163 impacts the integrity of data within the SmartCrawl SEO checker, analyzer & optimizer plugin for WordPress.