CyberRota Analysis
AI-GeneratedThe Slim SEO WordPress plugin prior to version 4.9.11 allows users with the Contributor role to access and read arbitrary post meta data, including sensitive information from protected and private posts, due to inadequate restrictions on the post-meta preview feature. This vulnerability can lead to unauthorized exposure of confidential data, potentially compromising user privacy and security. WordPress site administrators, especially those using this plugin, should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed to edit, verifying only read access, allowing users with the Contributor role to read arbitrary post meta, including protected and private keys, of published posts they do not own, including password-protected posts and posts of non-public post types.