Robots.txt rewrite

Robots.txt rewrite has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for Robots.txt rewrite has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.

All of these findings were reported by Nabil Irawan. Robots.txt rewrite is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.7.35.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all Robots.txt rewrite vulnerabilities before they are exploited.

Most severe open issueCVSS 4.3CVE-2025-62148

Robots.txt rewrite <= 1.6.1 - Cross-Site Request Forgery

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
Robots.txt rewrite banner
Latestv1.6.1

Robots.txt rewrite

Eugen Bobrowski

Author

Eugen Bobrowski

5.0(2)
100/100
Last Updated
2017-11-28 (9y ago)
Active Installs
1,000+
Downloads
36,078
Requires WP
4.7+
Requires PHP
0+
Tested up to
WP 4.7.35
Created
2016-05-03 (11y ago)

Plugin provide to help search engines to indexing site correctly. A simple plugin to manage your robots.txt. Plugin donn’t create the file or edit it. This plugin edit WordPress output of robots.txt content. And get you a easy and usable interface to manage it. Features Drag-n-drop robots.txt paths Changing blog_public option form plugin settings page Site map field for robots.txt Robots.txt physical file checking.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C