← WordPress Vulnerabilities
WordPress security by component

Slim SEO

Slim SEO provides automated search engine optimization features for WordPress websites.

Slim SEO (slim-seo) is a WordPress plugin with 6 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 7.6.

Plugin slug: slim-seo

CVE-2026-62113: Slim SEO exposes a contributor-level object reference

Slim SEO through 4.10.0 has an insecure direct object reference reachable by an authenticated Contributor. The CNA vector requires no user interaction and rates confidentiality impact as low. The authoritative export does not identify the endpoint, action, object identifier, protected object, or data disclosed.

PublishedSep 11, 2026
Known safe version4.10.1
Published vulnerabilities for slim-seo
Safe version
Sep 11, 2026 CVE-2026-62113
Slim SEO exposes a contributor-level object reference
Slim SEO through 4.10.0 has an insecure direct object reference reachable by an authenticated Contributor. The CNA vector requires no user interaction and rates confidentiality impact as low. The authoritative export does not identify the endpoint, action, object identifier, protected object, or data disclosed.
4.10.1
CVE4.3
NVDPending
Aug 09, 2026 CVE-2026-16957
Slim SEO preview feature exposes protected post metadata to Contributors
Slim SEO before 4.9.11 checks only whether a user can read a post before returning its metadata preview and does not verify edit access. A Contributor can read arbitrary metadata, including protected and private keys, from published posts they do not own, including password-protected posts and posts belonging to non-public post types.
4.9.11
CVE2.7
NVDPending
Jul 01, 2026 CVE-2026-12408
Slim SEO – A Fast & Automated SEO Plugin For WordPress: A security weakness
Slim SEO – A Fast & Automated SEO Plugin For WordPress is affected by a security weakness. Exploitation requires an authenticated contributor account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 4.9.8.
See mitigation notes
CVE4.3
NVDPending
Jun 25, 2026 CVE-2026-57429
Slim SEO: Broken access control
Slim SEO is affected by broken access control. Exploitation requires an authenticated contributor account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 4.6.2.
4.7.0
CVE6.5
NVDPending
Jun 17, 2025 CVE-2025-49854
Slim SEO: SQL injection
Slim SEO is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVDPending
May 21, 2025 CVE-2025-4611
Slim SEO – Fast & Automated WordPress SEO Plugin: Cross-site scripting
Slim SEO – Fast & Automated WordPress SEO Plugin is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending