Junglewise Threat Intelligence

CVE-2026-62113: Slim SEO Insecure Direct Object References in contributor endpoints

CVE-2026-62113 · Severity: medium · CVSS 4.3 · Published 2026-09-11

Executive brief

Slim SEO is a popular WordPress SEO optimization plugin. The vulnerability allows authenticated users with contributor-level permissions to access and potentially modify data belonging to other users by manipulating object identifiers in URLs. This could lead to exposure of sensitive data or unauthorized modification of content.

Technical details

The vulnerability is an Insecure Direct Object References (IDOR) flaw in Slim SEO versions up to 4.10.0 that affects contributor-level endpoints. An authenticated user with contributor privileges can change numeric IDs in URLs to access or manipulate objects (such as posts or settings) belonging to other users. The attack requires authentication as a contributor but no special privileges. The vulnerability was patched in version 4.10.1.

Affected products

  • eLightUp Slim SEO <= 4.10.0

Timeline

  • 2026-08-31: disclosed: Reported by Sybre Waaijer
  • 2026-09-11: advisory: Published by Patchstack
  • 2026-09-11: patched: Version 4.10.1 released

References

Related threats