MEDIUM

CVE-2026-57429

2026-06-25 CVSS v3.1
CVSS
6.5

Description

Contributor Broken Access Control in Slim SEO <= 4.6.2 versions.

Summary dbcve.org

This is a broken access control vulnerability in the Slim SEO WordPress plugin affecting versions 4.6.2 and below. Users with the 'contributor' role (who normally can only create but not publish content) can likely access or perform administrative functions they should not have permission to access, due to insufficient capability checks in the plugin code.

Mitigation

Update Slim SEO plugin to a version newer than 4.6.2. If no update is available, consider restricting contributor role capabilities or disabling the plugin until a patch is released.

Weakness (CWE)

CWE-862 Missing Authorization

EPSS Score

0.34%
Probability of exploitation in next 30 days
27.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE