Insecure Direct Object Reference in Slim SEO Plugin by WordPress
CVE-2026-62113

4.3MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-62113?

The Slim SEO plugin for WordPress versions prior to 4.10.0 is susceptible to Insecure Direct Object References (IDOR). This vulnerability allows attackers to access restricted resources by manipulating URLs or other input parameters. Attackers could exploit this flaw to gain unauthorized access, potentially leading to data exposure or manipulation. It is recommended that website owners update to the latest version of the Slim SEO plugin to mitigate the risks associated with this vulnerability.

Affected Version(s)

Slim SEO <= 4.10.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sybre Waaijer | Patchstack Bug Bounty Program
.