Simple SEO
Simple SEO has 6 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2025; all 6 are fixed as of September 2026. Their average CVSS score is 7.0, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 2 high. 2022 was the busiest year with 4 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 3 of the records (50%). Other recurring categories include Cross-Site Scripting.
Every one of the 6 issues recorded for Simple SEO has a vendor fix available, so running the current release closes all known holes.
3 independent researchers contributed these findings, most of them (3) reported by Kévin Mosbahi (Mika). Simple SEO is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2022-36404Simple SEO <= 1.8.12 - Cross-Site Request Forgery to Sitemap Deletion/Creation
Read the full analysisVulnerability Records
Simple SEO
Author
David Cole
Nonce Security! Generates META tags automatically. Works out-of-the-box. Just install! You can override any title and set any META description and any META keywords you want! Google Analytic 4! Google Webmaster Tools! Bing verification & Yandex verification! Twitter and Facebook customization! Quickedit SEO titles and descriptions! Import Yoast SEO data! Import Rank Math SEO data! Import All In One SEO data! Sitemaps! Supports custom post types!
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C