VYPR

Slim Seo

by WordPress

Source repositories

CVEs (5)

  • CVE-2025-49854HigJun 17, 2025
    risk 0.49cvss 7.6epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Anh Tran Slim SEO slim-seo allows SQL Injection.This issue affects Slim SEO: from n/a through <= 4.5.4.

  • CVE-2025-4611MedMay 21, 2025
    risk 0.35cvss 6.4epss 0.01

    The Slim SEO – Fast & Automated WordPress SEO Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's slim_seo_breadcrumbs shortcode in all versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping on user…

  • CVE-2026-16957LowAug 9, 2026
    risk 0.18cvss 2.7epss 0.00

    The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed to edit, verifying only read access, allowing users with the Contributor role to read arbitrary post meta, including protected and private keys, of published…

  • CVE-2026-12408MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    The Slim SEO – A Fast & Automated SEO Plugin For WordPress plugin for WordPress is vulnerable to Unauthorized Private Content Disclosure in all versions up to, and including, 4.9.8 via the `/wp-json/slim-seo/meta-tags/ai` REST API endpoint. This is due to the endpoint's…

  • CVE-2026-57429MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    Contributor Broken Access Control in Slim SEO <= 4.6.2 versions.