Executive brief
Slim SEO is a WordPress plugin used to automate search engine optimization tasks. A security flaw in versions 4.6.2 and earlier allows users with low-level 'Contributor' accounts to bypass access controls. This could allow an internal user to access or modify SEO settings and data they should not have permission to view, potentially impacting the site's search visibility or exposing configuration details.
Technical details
A broken access control vulnerability (CWE-862: Missing Authorization) exists in the Slim SEO plugin for WordPress in versions up to and including 4.6.2. The issue stems from insufficient validation of user permissions for certain plugin functions. An authenticated attacker with a minimum of 'Contributor' role privileges can exploit this over the network without user interaction. Successful exploitation allows the attacker to access sensitive information or perform actions typically reserved for higher-privileged users. The vulnerability is resolved in version 4.7.0.
Affected products
- eLightUp Slim SEO <= 4.6.2
Timeline
- 2025-08-13: other: Reported by Abu Hurayra
- 2026-06-25: disclosed: Published by Patchstack
- 2026-06-25: patched: Fixed in version 4.7.0