Robots.txt rewrite
Robots.txt rewrite has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Robots.txt rewrite has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Nabil Irawan. Robots.txt rewrite is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.7.35.
CVE-2025-62148Robots.txt rewrite <= 1.6.1 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

Robots.txt rewrite
Author
Eugen Bobrowski
Plugin provide to help search engines to indexing site correctly. A simple plugin to manage your robots.txt. Plugin donn’t create the file or edit it. This plugin edit WordPress output of robots.txt content. And get you a easy and usable interface to manage it. Features Drag-n-drop robots.txt paths Changing blog_public option form plugin settings page Site map field for robots.txt Robots.txt physical file checking.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C