Simple SEO

Simple SEO has 6 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2025; all 6 are fixed as of September 2026. Their average CVSS score is 7.0, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 2 high. 2022 was the busiest year with 4 disclosures.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 3 of the records (50%). Other recurring categories include Cross-Site Scripting.

Every one of the 6 issues recorded for Simple SEO has a vendor fix available, so running the current release closes all known holes.

3 independent researchers contributed these findings, most of them (3) reported by Kévin Mosbahi (Mika). Simple SEO is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
7.0/ 10
Patch Coverage100%
Open

0

Fixed

6

Get automatic notifications for all Simple SEO vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2022-36404

Simple SEO <= 1.8.12 - Cross-Site Request Forgery to Sitemap Deletion/Creation

Read the full analysis

Vulnerability Records

6 records
Plugin Profile
Latestv2.0.36
4.7(33)
94/100
Last Updated
2026-09-10 (3d ago)
Active Installs
10,000+
Downloads
195,190
Requires WP
4.6.2+
Requires PHP
7.4+
Tested up to
WP 7.0.4
Created
2017-02-15 (10y ago)

Nonce Security! Generates META tags automatically. Works out-of-the-box. Just install! You can override any title and set any META description and any META keywords you want! Google Analytic 4! Google Webmaster Tools! Bing verification & Yandex verification! Twitter and Facebook customization! Quickedit SEO titles and descriptions! Import Yoast SEO data! Import Rank Math SEO data! Import All In One SEO data! Sitemaps! Supports custom post types!

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C