Executive brief
CrawlWP SEO (also known as Index Now) is a WordPress plugin used to help search engines index website content more efficiently. A security flaw in this plugin could allow an attacker to trick a site administrator into performing unintended configuration changes or actions. This occurs if the administrator clicks on a malicious link or visits a specially crafted webpage while logged into their WordPress site.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the properfraction CrawlWP SEO plugin (also known as Index Now) for WordPress in versions up to and including 3.0.16. The vulnerability stems from a lack of proper nonce validation on sensitive plugin actions. An unauthenticated remote attacker can exploit this by tricking a privileged user (such as an administrator) into clicking a malicious link or submitting a crafted form. Successful exploitation allows the attacker to perform unauthorized actions or change plugin settings on behalf of the authenticated user. The issue is resolved in version 3.0.17.
Affected products
- properfraction CrawlWP SEO (Index Now) n/a through 3.0.16
Timeline
- 2026-06-30: other: Reported by researcher Ananda Dhakal
- 2026-07-05: disclosed: Early warning sent to Patchstack customers
- 2026-07-05: advisory: Public advisory published by Patchstack and NVD
- 2026-07-05: patched: Patch released in version 3.0.17