Impact
The Slim SEO plugin fails to sanitize and escape attributes supplied to its slim_seo_breadcrumbs shortcode, allowing an authenticated user with contributor or higher privileges to embed arbitrary JavaScript into the site’s content. When a page containing the injected shortcode is viewed, the malicious script executes in the visitor’s browser, potentially enabling credential theft, session hijacking, or site defacement.
Affected Systems
WordPress sites that have installed the Slim SEO – A Fast & Automated SEO Plugin For WordPress plugin in any version up to and including 4.5.3 are affected. The vulnerability exists in all such installations regardless of other configuration settings.
Risk and Exploitability
The CVSS score of 6.4 classifies the issue as moderate severity, and an EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with contributor access who can edit content or shortcode attributes; the attacker then inserts malicious code that persists until removed. If exploited, every user who loads a page containing the injected shortcode will run the attacker’s script.
OpenCVE Enrichment
EUVD