What is CVE-2026-16957?
A vulnerability in the Slim SEO WordPress plugin before version 4.9.11 allows users with the Contributor role to read arbitrary post meta, including protected and private keys, of published posts they do not own due to insufficient restrictions on a post-meta preview feature. Immediate update to the latest patched version is strongly recommended.
Azərbaycanca: Slim SEO WordPress plagininin 4.9.11 versiyasına qədər olan versiyalarında Contributor rolu ilə istifadəçilərin öz səlahiyyətləri xaricindəki yazıların həssas post-meta məlumatlarını oxumasına imkan verən zəiflik aşkar edilmişdir. Plagininizi dərhal ən son versiyaya yeniləməyiniz tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the Slim SEO plugin are affected by CVE-2026-16957?
This vulnerability affects the Slim SEO WordPress plugin in versions before 4.9.11.
What user role can exploit this vulnerability in the Slim SEO plugin?
This vulnerability in the Slim SEO plugin can be exploited by users with the Contributor role.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.