WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Surfer – WordPress Plugin

Connect Surfer's Content Editor to WordPress. Write and optimize your articles for SEO, find new keyword ideas and publish straight to WordPress.

3Reported vulnerabilities
5.4Highest CVSS score
1.7.0.639Latest version
6,000+Active installs

What to do now

Update Surfer – WordPress Plugin to 1.6.5.584 or later. 3 of these have a fixed version available. Updating resolves them.

Plugin last updated: April 28, 2026 / Tested up to WordPress: 6.9.7 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2023-35037 Medium 5.4 0.5% 1.3.2.357 and earlier 1.3.3.379 September 1, 2023
CVE-2025-58603 Medium 5.3 0.3% 1.6.4.574 and earlier 1.6.5.584 September 3, 2025
CVE-2024-49299 Medium 4.9 0.4% 1.5.0.502 and earlier 1.6.0.523 October 15, 2024

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.