WordPress security by component
Slim SEO
Plugin description
Slim SEO provides automated search engine optimization features for WordPress websites.
Slim SEO (slim-seo) is a WordPress plugin with 6 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 7.6.
Plugin slug:
slim-seoLatest vulnerability
CVE-2026-62113: Slim SEO exposes a contributor-level object reference
Slim SEO through 4.10.0 has an insecure direct object reference reachable by an authenticated Contributor. The CNA vector requires no user interaction and rates confidentiality impact as low. The authoritative export does not identify the endpoint, action, object identifier, protected object, or data disclosed.
| Safe version |
|
||
|---|---|---|---|
| Sep 11, 2026 |
CVE-2026-62113
Slim SEO exposes a contributor-level object reference
Slim SEO through 4.10.0 has an insecure direct object reference reachable by an authenticated Contributor. The CNA vector requires no user interaction and rates confidentiality impact as low. The authoritative export does not identify the endpoint, action, object identifier, protected object, or data disclosed.
|
4.10.1 |
CVE4.3
NVDPending
|
| Aug 09, 2026 |
CVE-2026-16957
Slim SEO preview feature exposes protected post metadata to Contributors
Slim SEO before 4.9.11 checks only whether a user can read a post before returning its metadata preview and does not verify edit access. A Contributor can read arbitrary metadata, including protected and private keys, from published posts they do not own, including password-protected posts and posts belonging to non-public post types.
|
4.9.11 |
CVE2.7
NVDPending
|
| Jul 01, 2026 |
CVE-2026-12408
Slim SEO – A Fast & Automated SEO Plugin For WordPress: A security weakness
Slim SEO – A Fast & Automated SEO Plugin For WordPress is affected by a security weakness. Exploitation requires an authenticated contributor account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 4.9.8.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jun 25, 2026 |
CVE-2026-57429
Slim SEO: Broken access control
Slim SEO is affected by broken access control. Exploitation requires an authenticated contributor account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 4.6.2.
|
4.7.0 |
CVE6.5
NVDPending
|
| Jun 17, 2025 |
CVE-2025-49854
Slim SEO: SQL injection
Slim SEO is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.6
NVDPending
|
| May 21, 2025 |
CVE-2025-4611
Slim SEO – Fast & Automated WordPress SEO Plugin: Cross-site scripting
Slim SEO – Fast & Automated WordPress SEO Plugin is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|