MEDIUM
CVE-2026-57429
CVSS
6.5
Description
Contributor Broken Access Control in Slim SEO <= 4.6.2 versions.
Summary dbcve.org
This is a broken access control vulnerability in the Slim SEO WordPress plugin affecting versions 4.6.2 and below. Users with the 'contributor' role (who normally can only create but not publish content) can likely access or perform administrative functions they should not have permission to access, due to insufficient capability checks in the plugin code.
Mitigation
Update Slim SEO plugin to a version newer than 4.6.2. If no update is available, consider restricting contributor role capabilities or disabling the plugin until a patch is released.
Weakness (CWE)
CWE-862
Missing Authorization
EPSS Score
0.34%
Probability of exploitation in next 30 days
27.6th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.