AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-16957

LOW · CVSS 2.7 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-09 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The Slim SEO WordPress plugin prior to version 4.9.11 allows users with the Contributor role to access and read arbitrary post meta data, including sensitive information from protected and private posts, due to inadequate restrictions on the post-meta preview feature. This vulnerability can lead to unauthorized exposure of confidential data, potentially compromising user privacy and security. WordPress site administrators, especially those using this plugin, should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-16957
Severity
LOW
CVSS
2.7
EPSS
0.18%
WordPress

Original NVD Description

The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed to edit, verifying only read access, allowing users with the Contributor role to read arbitrary post meta, including protected and private keys, of published posts they do not own, including password-protected posts and posts of non-public post types.