Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Slim SEO <= 4.9.8 - Authenticated (Contributor+) Insufficient Authorization to Private Content Disclosure via 'object.ID' Parameter
Vulnerability Description
The Slim SEO – A Fast & Automated SEO Plugin For WordPress plugin for WordPress is vulnerable to Unauthorized Private Content Disclosure in all versions up to, and including, 4.9.8 via the `/wp-json/slim-seo/meta-tags/ai` REST API endpoint. This is due to the endpoint's `permission_callback` performing only a top-level `edit_posts` capability check without verifying that the requesting user has read access to the specific post supplied via the `object.ID` parameter, allowing the `generate` function to pass the attacker-controlled post ID to `Data::get_post_content()`, which calls `get_post()` regardless of post status or ownership. This makes it possible for authenticated attackers with Contributor-level access and above to retrieve AI-generated summaries of the raw `post_content` of arbitrary posts they are not authorized to view — including private posts, drafts, pending, future, and password-protected content authored by other users — with the substance of the protected content disclosed via the HTTP response.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
信息暴露
Vulnerability Title
WordPress Slim SEO 信息泄露漏洞
Vulnerability Description
eLightUp Slim SEO是eLightUp公司的一款快速自动化的WordPress SEO插件。 WordPress Slim SEO存在信息泄露漏洞,该漏洞源于端点权限检查不完整,仅执行顶级的edit_posts能力检查,未验证用户对特定object.ID参数指定帖子的读取权限,导致具有贡献者及以上权限的认证攻击者能够检索作者设置为私有、草稿等受保护内容的AI生成摘要,造成未授权私有内容泄露。以下版本受到影响:4.9.8及之前版本。
CVSS Information
N/A
Vulnerability Type
N/A