Executive brief
Slim SEO is a popular WordPress SEO optimization plugin. The vulnerability allows authenticated users with contributor-level permissions to access and potentially modify data belonging to other users by manipulating object identifiers in URLs. This could lead to exposure of sensitive data or unauthorized modification of content.
Technical details
The vulnerability is an Insecure Direct Object References (IDOR) flaw in Slim SEO versions up to 4.10.0 that affects contributor-level endpoints. An authenticated user with contributor privileges can change numeric IDs in URLs to access or manipulate objects (such as posts or settings) belonging to other users. The attack requires authentication as a contributor but no special privileges. The vulnerability was patched in version 4.10.1.
Affected products
- eLightUp Slim SEO <= 4.10.0
Timeline
- 2026-08-31: disclosed: Reported by Sybre Waaijer
- 2026-09-11: advisory: Published by Patchstack
- 2026-09-11: patched: Version 4.10.1 released