Junglewise Threat Intelligence

CVE-2026-12408: Slim SEO WordPress plugin private content disclosure in AI REST API

CVE-2026-12408 · Severity: medium · CVSS 4.3 · Published 2026-07-01

Executive brief

Slim SEO, a popular WordPress plugin used to automate search engine optimization, contains a security flaw that allows unauthorized users to view private content. An attacker with a basic contributor account could use the plugin's AI features to generate summaries of restricted posts, including drafts and password-protected content. This could lead to the exposure of sensitive business information or unpublished articles before they are ready for public release.

Technical details

The vulnerability exists in the `/wp-json/slim-seo/meta-tags/ai` REST API endpoint due to an insufficient `permission_callback` implementation. While the endpoint checks for the general `edit_posts` capability, it fails to verify if the requesting user has specific read access to the post ID provided in the `object.ID` parameter. The `generate` function subsequently passes this ID to `Data::get_post_content()`, which retrieves the content using `get_post()` regardless of the post's status (private, draft, pending) or ownership. Consequently, an authenticated attacker with Contributor-level permissions can disclose the substance of protected content via the AI-generated summaries returned in the HTTP response.

Affected products

  • rilwis Slim SEO – A Fast & Automated SEO Plugin For WordPress up to, and including, 4.9.8

Timeline

  • 2026-07-01: advisory: NVD publication date

References