CVE-2025-4611
Published
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
2
PROJECTS
Description
The Slim SEO – Fast & Automated WordPress SEO Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's slim_seo_breadcrumbs shortcode in all versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
<h3>A Fast & Automated SEO Plugin For WordPress</h3>
<p>Currently there are many SEO plugins for WordPress in the market. But these plugins often have too many options and are very complicated for ordinary users. Access to their configuration section, you will easily get lost in a maze of explanations and options that you sometimes don’t understand. Besides, there are ads!</p>
<p><strong>So how can an ordinary user use an SEO plugin?</strong></p>
<p>SEO should be an integrated part of WordPress, where users don’t need or need very little effort to configure for SEO. The main reason is that not everyone understands the terms of SEO and how to configure them optimally.</p>
<p>So, we made <a href="https://wpslimseo.com" rel="nofollow ugc"><strong>Slim SEO</strong></a>.</p>
<p><span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/MVNjGAiu2bg?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span></p>
<p><span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/vnC94TMn3wU?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span></p>
<p>Slim SEO is a full-featured SEO plugin, that’s done right! It provides a complete SEO solution for WordPress where the configuration has been done automatically. Users do not need to care about their complex and semantic options.</p>
<p>So what does Slim SEO do?</p>
<h3>Slim SEO Features</h3>
<p>Slim SEO helps you do the following jobs automatically:</p>
<h4>1. Meta Tags</h4>
<p>The following meta tags are auto-generated and optimized for the best SEO scores.</p>
<ul>
<li><a href="https://docs.wpslimseo.com/slim-seo/meta-title-tag/" rel="nofollow ugc">Meta title tag</a>: display your title in a SEO-friendly way.</li>
<li><a href="https://docs.wpslimseo.com/slim-seo/meta-description-tag/" rel="nofollow ugc">Meta description tag</a>: auto generate from posts/pages excerpt or content.</li>
<li><a href="https://docs.wpslimseo.com/slim-seo/meta-robots-tag/" rel="nofollow ugc">Meta robots tag</a>: decide which pages are indexed and which ones not.</li>
<li><a href="https://docs.wpslimseo.com/slim-seo/facebook-open-graph-tags/" rel="nofollow ugc">Facebook Open Graph Tags</a>: share your posts on Facebook beautifully.</li>
<li><a href="https://docs.wpslimseo.com/slim-seo/twitter-card-tags/" rel="nofollow ugc">Twitter Card Tags</a>: share your posts on Twitter beautifully.</li>
<li>LinkedIn meta tags</li>
</ul>
<h4>2. <a href="https://docs.wpslimseo.com/slim-seo/xml-sitemap/" rel="nofollow ugc">XML Sitemap</a></h4>
<p>Slim SEO automatically generates XML sitemap (at <code>domain.com/sitemap.xml</code>) to submit to search engines. With XML sitemaps, your website are indexed fast and completely.</p>
<p>Besides the normal XML sitemap, Slim SEO also includes sitemaps for images and Google news.</p>
<h4>3. <a href="https://docs.wpslimseo.com/slim-seo/breadcrumbs/" rel="nofollow ugc">Breadcrumbs</a></h4>
<p>The plugin allows you to output a breadcrumb trail on your website easily. It automatically fetches the information from the current post and output a hierarchy for you. You can also style the breadcrumbs to match your theme style.</p>
<h4>4. <a href="https://docs.wpslimseo.com/slim-seo/schema/" rel="nofollow ugc">Schema (Structured Data)</a></h4>
<p>Schema is a way that describes structured data for search engines. Based on the data provided, search engines can show the content in the search results page in a more appealing way.</p>
<p>Slim SEO automatically adds the some structured data to the website via JSON-LD which makes your website more SEO-friendly. Not only schemas are created by the plugin, there are also meaningful connections between them. For example, an article (single post) is the main entity of the current webpage. Slim SEO does that all without any configuration.</p>
<h4>5. <a href="https://docs.wpslimseo.com/slim-seo/redirection/" rel="nofollow ugc">Redirection</a></h4>
<ul>
<li>Setting up redirection rules easily</li>
<li>Auto redirect non-www to www and vice versa</li>
<li>404 link monitoring</li>
</ul>
<h4>6. And many more</h4>
<ul>
<li><a href="https://docs.wpslimseo.com/slim-seo/header-footer-code/" rel="nofollow ugc">Inserting Google Analytics, Facebook pixel or any code to the header or footer</a> of the site</li>
<li>Auto prevent scraping content from <a href="https://docs.wpslimseo.com/slim-seo/rss-feed/" rel="nofollow ugc">RSS feed</a></li>
<li><a href="https://docs.wpslimseo.com/slim-seo/integrations/" rel="nofollow ugc">Integrations</a> with many plugins, including page builders</li>
<li><a href="https://docs.wpslimseo.com/slim-seo/import-export/" rel="nofollow ugc">Import and export</a> data or migrate data from popular SEO plugins</li>
<li>Auto redirect if post slug changed</li>
</ul>
<h3>Slim SEO Pro</h3>
<p>Upgrade to <a href="https://elu.to/wrp" rel="nofollow ugc">Slim SEO Pro</a> to have access to advanced SEO features without complexity:</p>
<ul>
<li>Visual schema builder</li>
<li>30+ pre-built schema types</li>
<li>Custom schema with JSON-LD</li>
<li>Contextual link suggestions</li>
<li>Real-time link health monitoring</li>
<li>Broken link repair</li>
<li>Link updater</li>
<li>View search performance with Google Search Console integration</li>
<li>Improve your content with writing assistant</li>
</ul>
<p><a href="https://elu.to/wrp" rel="nofollow ugc">Get Slim SEO Pro now</a>.</p>
<h3>Who should use Slim SEO?</h3>
<p>Everyone can use Slim SEO!</p>
<p>However, Slim SEO is perfectly suitable for users who prefer simplicity or do not like the complicated options that other SEO plugins provide. It’s also a good choice for users with little SEO knowledge and just want to use SEO plugins to automate their jobs.</p>
<h3>You might also like</h3>
<p>If you like this plugin, you might also like our other WordPress products:</p>
<ul>
<li><a href="https://metabox.io" rel="nofollow ugc">Meta Box</a> – A powerful WordPress plugin for creating custom post types and custom fields.</li>
<li><a href="https://wpfalcon.pro" rel="nofollow ugc">Falcon</a> – A lightweight companion for making WordPress faster, cleaner, and more secure.</li>
<li><a href="https://gretathemes.com" rel="nofollow ugc">GretaThemes</a> – Free and premium WordPress themes that clean, simple and just work.</li>
<li><a href="https://wpautolistings.com" rel="nofollow ugc">Auto Listings</a> – A car sale and dealership plugin for WordPress.</li>
</ul>