Noindex by Path
Noindex by Path has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Noindex by Path has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Skalucy. Noindex by Path is installed on roughly 60 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.7.35.
CVE-2025-49353Noindex by Path <= 1.0 - Cross-Site Request Forgery
Read the full analysisVulnerability Records
Noindex by Path
Author
Marcin Kijak
After installation you can find “Noindex by path” option in the main menu. This allows you to simply add relative paths you need to exclude from SERPs. Add a path (including slashes from begging and the end of the string) and save the changes. Since this plugin is called to be “simple” you can add only one path at once, but the process is smooth and easy. Plugin will add “noindex” meta tag which is an instruction for search engines that this particular page should not be indexed. Technically it modifies wp_head tag.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C