Slim SEO <= 4.9.10 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Post Meta Disclosure
medium
The Slim SEO plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.9.10. This is due to insufficient capability check in the can_edit_post() REST API permission callback using edit_posts and read_post instead of the post-specific edit_post capability. This makes it p...
- CVSS:
- 4.3
- Affected:
- up to 4.9.10
- Fixed in:
- 4.9.11
- Disclosed:
- Aug 3, 2026
CVE-2026-16957 on NVD →
Slim SEO <= 4.9.8 - Authenticated (Contributor+) Insufficient Authorization to Private Content Disclosure via 'object.ID' Parameter
medium
The Slim SEO – A Fast & Automated SEO Plugin For WordPress plugin for WordPress is vulnerable to Unauthorized Private Content Disclosure in all versions up to, and including, 4.9.8 via the `/wp-json/slim-seo/meta-tags/ai` REST API endpoint. This is due to the endpoint's `permission_callback` performing only a top-level...
- CVSS:
- 4.3
- Affected:
- up to 4.9.8
- Fixed in:
- 4.9.9
- Disclosed:
- Jun 30, 2026
CVE-2026-12408 on NVD →
Slim SEO – A Fast & Automated SEO Plugin For WordPress <= 4.6.2 - Missing Authorization
medium
The Slim SEO – A Fast & Automated SEO Plugin For WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.6.2. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unautho...
- CVSS:
- 4.3
- Affected:
- up to 4.6.2
- Fixed in:
- 4.7.0
- Disclosed:
- Jun 25, 2026
CVE-2026-57429 on NVD →
Slim SEO – Fast & Automated WordPress SEO Plugin [slim-seo] < 4.5.5
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Anh Tran Slim SEO allows SQL Injection. This issue affects Slim SEO: from n/a through 4.5.4.
- Affected:
- up to 4.5.5
- Fixed in:
- 4.5.5
- Disclosed:
- Jun 17, 2025
CVE-2025-49854 on NVD →
Slim SEO <= 4.5.4 - Authenticated (Administrator+) SQL Injection
medium
The Slim SEO plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and abov...
- CVSS:
- 4.9
- Affected:
- up to 4.5.4
- Fixed in:
- 4.5.5
- Disclosed:
- Jun 12, 2025
CVE-2025-49854 on NVD →
Slim SEO <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via slim_seo_breadcrumbs Shortcode
medium
The Slim SEO – Fast & Automated WordPress SEO Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's slim_seo_breadcrumbs shortcode in all versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possibl...
- CVSS:
- 6.4
- Affected:
- up to 4.5.3
- Fixed in:
- 4.5.4
- Disclosed:
- May 20, 2025
CVE-2025-4611 on NVD →
Slim SEO – Fast & Automated WordPress SEO Plugin [slim-seo] < 4.5.4
unknown
- Affected:
- up to 4.5.4
- Fixed in:
- 4.5.4
CVE-2025-4611 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database