CVE-2026-16618 PUBLISHED

ImproveSEO <= 2.0.11 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execution

Assigner: WPScan
Reserved: 22.07.2026 Published: 04.08.2026 Updated: 04.08.2026

The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file with the attacker-supplied extension into a publicly accessible directory, allowing unauthenticated users to upload executable PHP files and achieve remote code execution.

Product Status

Vendor Unknown
Product Improve SEO
Versions Default: unknown
  • affected from 0 to 2.0.11 (incl.)

Credits

  • João Ramos Maciel finder
  • WPScan coordinator

References

Problem Types

  • CWE-434 Unrestricted Upload of File with Dangerous Type CWE