Slider Revolution 7.0.0-7.0.16 - Unauthenticated Stored Cross-Site Scripting
high
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 7.0.0-7.0.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an i...
- CVSS:
- 7.2
- Affected:
- 7.0.0 – 7.0.16
- Fixed in:
- 7.1.0
- Disclosed:
- Jun 30, 2026
CVE-2026-57678 on NVD →
Slider Revolution 7.0 - 7.0.10 - Authenticated (Subscriber+) Sensitive Information Disclosure
medium
The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions 7.0 to 7.0.10. This is due to three compounding design flaws: (1) the plugin leaks a valid backend AJAX nonce (revslider_actions) to all authenticated users including Subscribers via the admin_footer hook; (2) the w...
- CVSS:
- 6.5
- Affected:
- 7.0 – 7.0.10
- Fixed in:
- 7.0.11
- Disclosed:
- Jun 8, 2026
CVE-2026-7542 on NVD →
Slider Revolution 6.0.0-6.7.55 and 7.0.0-7.0.14 - Missing Authorization to Authenticated (Contributor+) Arbitrary Plugin Deactivation
medium
The Slider Revolution plugin for WordPress in versions 6.0.0-6.7.55 and 7.0.0-7.0.14 is vulnerable to unauthorized modification of data. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Contributor-level access and...
- CVSS:
- 4.3
- Affected:
- 6.0.0 – 6.7.55, 7.0.0 – 7.0.14
- Fixed in:
- 6.7.56
- Disclosed:
- Jun 1, 2026
CVE-2026-9050 on NVD →
Slider Revolution 7.0.0 - 7.0.14 - Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure
medium
The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 7.0.0 - 7.0.14, via the 'slider.get.full' AJAX Action. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including raw social media API credentials:...
- CVSS:
- 4.3
- Affected:
- 7.0.0 – 7.0.14
- Fixed in:
- 7.0.15
- Disclosed:
- Jun 1, 2026
CVE-2026-9048 on NVD →
Slider Revolution <= 7.0.9 - Unauthenticated Sensitive Information Exposure via 'sliders/stream'
medium
The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.0.9 via the 'get_stream_data()' function. This makes it possible for unauthenticated attackers to extract sensitive data including published password-protected post, page, and product content.
- CVSS:
- 5.3
- Affected:
- 6.0 – 6.7.54, 7.0 – 7.0.9
- Fixed in:
- 6.7.55
- Disclosed:
- May 19, 2026
CVE-2026-6728 on NVD →
Slider Revolution 7.0.0 - 7.0.10 - Authenticated (Subscriber+) Arbitrary File Upload via _get_media_url
high
The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0.0 to 7.0.10 via the '_get_media_url' and '_check_file_path' function. This is due to insufficient file type validation. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload...
- CVSS:
- 8.8
- Affected:
- 7.0.0 – 7.0.10
- Fixed in:
- 7.0.11
- Disclosed:
- May 6, 2026
CVE-2026-6692 on NVD →
Slider Revolution [revslider] < 6.7.38
unknown
[en] The Slider Revolution plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions in all versions up to, and including, 6.7.37. This makes it possible for authenticated attackers, with Contributor-level access and above, to install and a...
- Affected:
- up to 6.7.38
- Fixed in:
- 6.7.38
- Disclosed:
- Oct 9, 2025
CVE-2025-10249 on NVD →
Slider Revolution <= 6.7.37 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Read
medium
The Slider Revolution plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions in all versions up to, and including, 6.7.37. This makes it possible for authenticated attackers, with Contributor-level access and above, to install and activa...
- CVSS:
- 6.5
- Affected:
- up to 6.7.37
- Fixed in:
- 6.7.38
- Disclosed:
- Oct 8, 2025
CVE-2025-10249 on NVD →
Slider Revolution < 6.7.38 - Contributor+ Arbitrary File Read
medium
- Affected:
- up to 6.7.38
- Fixed in:
- 6.7.38
- Disclosed:
- Oct 8, 2025
CVE-2025-10249 on NVD →
Slider Revolution <= 6.7.36 - Authenticated (Contributor+) Arbitrary File Read via 'used_svg' and 'used_images'
medium
The Slider Revolution plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.7.36 via the 'used_svg' and 'used_images' parameters. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, whi...
- CVSS:
- 6.5
- Affected:
- up to 6.7.36
- Fixed in:
- 6.7.37
- Disclosed:
- Aug 28, 2025
CVE-2025-9217 on NVD →
Slider Revolution < 6.7.37 - Authenticated (Contributor+) Arbitrary File Read via 'used_svg' and 'used_images'
medium
- Affected:
- up to 6.7.37
- Fixed in:
- 6.7.37
- Disclosed:
- Aug 28, 2025
CVE-2025-9217 on NVD →
Slider Revolution [revslider] < 6.7.19
unknown
[en] The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arb...
- Affected:
- up to 6.7.19
- Fixed in:
- 6.7.19
- Disclosed:
- Oct 1, 2024
CVE-2024-8107 on NVD →
Slider Revolution <= 6.7.18 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
medium
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrar...
- CVSS:
- 6.4
- Affected:
- up to 6.7.18
- Fixed in:
- 6.7.19
- Disclosed:
- Sep 30, 2024
CVE-2024-8107 on NVD →
Slider Revolution < 6.7.19 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
medium
- Affected:
- up to 6.7.19
- Fixed in:
- 6.7.19
- Disclosed:
- Sep 30, 2024
CVE-2024-8107 on NVD →
Slider Revolution [revslider] < 6.7.14
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a through 6.7.13.
- Affected:
- up to 6.7.14
- Fixed in:
- 6.7.14
- Disclosed:
- Jul 21, 2024
CVE-2024-37449 on NVD →
Slider Revolution <= 6.7.13 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.7.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in p...
- CVSS:
- 4.4
- Affected:
- up to 6.7.13
- Fixed in:
- 6.7.14
- Disclosed:
- Jun 28, 2024
CVE-2024-37449 on NVD →
Slider Revolution < 6.7.14 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
- Affected:
- up to 6.7.14
- Fixed in:
- 6.7.14
- Disclosed:
- Jun 28, 2024
CVE-2024-37449 on NVD →
Slider Revolution [revslider] < 6.7.11
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemePunch OHG Slider Revolution allows Stored XSS.This issue affects Slider Revolution: from n/a before 6.7.11.
- Affected:
- up to 6.7.11
- Fixed in:
- 6.7.11
- Disclosed:
- Jun 19, 2024
CVE-2024-34443 on NVD →
Slider Revolution [revslider] < 6.7.0
unknown
[en] Missing Authorization vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a before 6.7.0.
- Affected:
- up to 6.7.0
- Fixed in:
- 6.7.0
- Disclosed:
- Jun 19, 2024
CVE-2024-34444 on NVD →
Slider Revolution [revslider] < 6.7.11
unknown
[en] The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Add Layer widget in all versions up to, and including, 6.7.11 due to insufficient input sanitization and output escaping on the user supplied 'class', 'id', and 'title' attributes. This makes it possible for au...
- Affected:
- up to 6.7.11
- Fixed in:
- 6.7.11
- Disclosed:
- Jun 4, 2024
CVE-2024-4581 on NVD →
Slider Revolution [revslider] < 6.7.11
unknown
[en] The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.7.10 due to insufficient input sanitization and output escaping on the user supplied Elementor 'wrapperid' and 'zindex' display attributes. This makes it possible for authenticated attack...
- Affected:
- up to 6.7.11
- Fixed in:
- 6.7.11
- Disclosed:
- Jun 4, 2024
CVE-2024-4637 on NVD →
Slider Revolution <= 6.7.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Elementor wrapperid and zindex
medium
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.7.10 due to insufficient input sanitization and output escaping on the user supplied Elementor 'wrapperid' and 'zindex' display attributes. This makes it possible for authenticated attackers,...
- CVSS:
- 6.4
- Affected:
- up to 6.7.10
- Fixed in:
- 6.7.11
- Disclosed:
- Jun 3, 2024
CVE-2024-4637 on NVD →
Slider Revolution <= 6.7.11 - Authenticated (Author+) Stored Cross-Site Scripting via Add Layer class, id, and title Attributes
medium
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Add Layer widget in all versions up to, and including, 6.7.11 due to insufficient input sanitization and output escaping on the user supplied 'class', 'id', and 'title' attributes. This makes it possible for authent...
- CVSS:
- 6.4
- Affected:
- up to 6.7.10
- Fixed in:
- 6.7.11
- Disclosed:
- Jun 3, 2024
CVE-2024-4581 on NVD →
Slider Revolution < 6.7.11 - Authenticated (Author+) Stored Cross-Site Scripting via Add Layer class, id, and title Attributes
medium
- Affected:
- up to 6.7.11
- Fixed in:
- 6.7.11
- Disclosed:
- Jun 3, 2024
CVE-2024-4581 on NVD →
Slider Revolution < 6.7.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Elementor wrapperid and zindex
medium
- Affected:
- up to 6.7.11
- Fixed in:
- 6.7.11
- Disclosed:
- Jun 3, 2024
CVE-2024-4637 on NVD →
Slider Revolution <= 6.7.10 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.7.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in page...
- CVSS:
- 6.4
- Affected:
- up to 6.7.10
- Fixed in:
- 6.7.11
- Disclosed:
- May 28, 2024
CVE-2024-34443 on NVD →
Slider Revolution <= 6.6.20 - Missing Authorization
medium
The Slider Revolution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init_rest_api function in versions up to 6.7.0. This makes it possible for unauthenticated attackers to update slider data.
- CVSS:
- 6.4
- Affected:
- up to 6.6.20
- Fixed in:
- 6.7.0
- Disclosed:
- May 28, 2024
CVE-2024-34444 on NVD →
Slider Revolution < 6.7.11 - Authenticated (Author+) Stored Cross-Site Scripting
medium
- Affected:
- up to 6.7.11
- Fixed in:
- 6.7.11
- Disclosed:
- May 28, 2024
CVE-2024-34443 on NVD →
Slider Revolution < 6.7.0 - Missing Authorization
medium
- Affected:
- up to 6.7.0
- Fixed in:
- 6.7.0
- Disclosed:
- May 28, 2024
CVE-2024-34444 on NVD →
Slider Revolution [revslider] < 6.7.8
unknown
[en] The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘htmltag’ parameter in all versions up to, and including, 6.7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages tha...
- Affected:
- up to 6.7.8
- Fixed in:
- 6.7.8
- Disclosed:
- May 2, 2024
CVE-2024-4092 on NVD →
Slider Revolution <= 6.7.7 - Authenticated (Author+) Stored Cross-Site Scripting via htmltag Parameter
medium
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘htmltag’ parameter in all versions up to, and including, 6.7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that wil...
- CVSS:
- 6.4
- Affected:
- up to 6.7.7
- Fixed in:
- 6.7.8
- Disclosed:
- Apr 30, 2024
CVE-2024-4092 on NVD →
Slider Revolution < 6.7.8 - Authenticated (Author+) Stored Cross-Site Scripting via htmltag Parameter
medium
- Affected:
- up to 6.7.8
- Fixed in:
- 6.7.8
- Disclosed:
- Apr 30, 2024
CVE-2024-4092 on NVD →
Slider Revolution [revslider] < 6.7.0
unknown
[en] The Revslider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg upload in all versions up to, and including, 6.6.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whene...
- Affected:
- up to 6.7.0
- Fixed in:
- 6.7.0
- Disclosed:
- Apr 9, 2024
CVE-2024-2306 on NVD →
Revslider <= 6.6.20 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Revslider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg upload in all versions up to, and including, 6.6.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a...
- CVSS:
- 6.4
- Affected:
- up to 6.6.20
- Fixed in:
- 6.7.0
- Disclosed:
- Apr 8, 2024
CVE-2024-2306 on NVD →
Revslider < 6.7.0 - Authenticated (Author+) Stored Cross-Site Scripting
medium
- Affected:
- up to 6.7.0
- Fixed in:
- 6.7.0
- Disclosed:
- Apr 8, 2024
CVE-2024-2306 on NVD →
Slider Revolution [revslider] < 6.6.19
unknown
[en] The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially leading to Remote Code Execution.
- Affected:
- up to 6.6.19
- Fixed in:
- 6.6.19
- Disclosed:
- Jan 8, 2024
CVE-2023-6528 on NVD →
Slider Revolution [revslider] < 6.6.16
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a through 6.6.15.
- Affected:
- up to 6.6.16
- Fixed in:
- 6.6.16
- Disclosed:
- Dec 20, 2023
CVE-2023-47784 on NVD →
Slider Revolution < 6.6.19 - Authenticated (Author+) PHP Object Injection
high
The Slider Revolution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 6.6.19 (exclusive) via deserialization of untrusted input when importing a new slider. This makes it possible for authenticated attackers, with author-level access and above, to inject a PHP Object. No known POP chain...
- CVSS:
- 8.8
- Affected:
- up to 6.6.19
- Fixed in:
- 6.6.19
- Disclosed:
- Nov 30, 2023
CVE-2023-6528 on NVD →
Slider Revolution < 6.6.19 - Author+ Insecure Deserialization leading to RCE
critical
- Affected:
- up to 6.6.19
- Fixed in:
- 6.6.19
- Disclosed:
- Nov 30, 2023
CVE-2023-6528 on NVD →
Slider Revolution [revslider] < 3.0.96
unknown
Update the plugin.
Simo Ben Youssef discovered and reported this Remote File Inclusion vulnerability in WordPress Slider Revolution Plugin. This could allow a malicious actor to get a website to load an external website or script which will then be executed on the website. This could allow the malicious actor to create...
- Affected:
- up to 3.0.96
- Fixed in:
- 3.0.96
- Disclosed:
- Nov 26, 2023
Slider Revolution [revslider] < 6.6.15
unknown
[en] Contributor+ Stored Cross-Site Scripting (XSS) vulnerability in Slider Revolution <= 6.6.14.
- Affected:
- up to 6.6.15
- Fixed in:
- 6.6.15
- Disclosed:
- Nov 20, 2023
CVE-2023-47772 on NVD →
Slider Revolution <= 6.6.15 - Authenticated (Author+) Arbitrary File Upload
high
The Slider Revolution plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 6.6.15. This makes it possible for attackers with author-level access and higher to upload arbitrary files on the affected site's server which may make remote code execution possible.
- CVSS:
- 7.2
- Affected:
- up to 6.6.15
- Fixed in:
- 6.6.16
- Disclosed:
- Nov 14, 2023
CVE-2023-47784 on NVD →
Slider Revolution <= 6.6.14 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.6.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pag...
- CVSS:
- 6.4
- Affected:
- up to 6.6.14
- Fixed in:
- 6.6.15
- Disclosed:
- Nov 14, 2023
CVE-2023-47772 on NVD →
Slider Revolution < 6.6.16 - Authenticated (Author+) Arbitrary File Upload
critical
- Affected:
- up to 6.6.16
- Fixed in:
- 6.6.16
- Disclosed:
- Nov 14, 2023
CVE-2023-47784 on NVD →
Slider Revolution < 6.6.15 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
- Affected:
- up to 6.6.15
- Fixed in:
- 6.6.15
- Disclosed:
- Nov 14, 2023
CVE-2023-47772 on NVD →
Slider Revolution [revslider] < 6.6.13
unknown
[en] The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Execution in some server configurations.
- Affected:
- up to 6.6.13
- Fixed in:
- 6.6.13
- Disclosed:
- Jun 19, 2023
CVE-2023-2359 on NVD →
Slider Revolution <= 6.6.12 - Authenticated (Administrator+) Arbitrary File Upload
high
The Slider Revolution plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in versions up to, and including, 6.6.12. This makes it possible for authenticated attackers with administrator-level attackers to upload arbitrary files on the affected site's server which may make re...
- CVSS:
- 7.2
- Affected:
- up to 6.6.12
- Fixed in:
- 6.6.13
- Disclosed:
- May 22, 2023
CVE-2023-2359 on NVD →
Revolution Slider <= 6.6.12 - Author+ Remote Code Execution
critical
- Affected:
- up to 6.6.13
- Fixed in:
- 6.6.13
- Disclosed:
- May 22, 2023
CVE-2023-2359 on NVD →
Slider Revolution [revslider] < 4.2.3
unknown
[en] Cross-site scripting (XSS) vulnerability in the Slider Revolution (revslider) plugin 4.2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the client_action parameter in a revslider_ajax_action action to wp-admin/admin-ajax.php.
- Affected:
- up to 4.2.3
- Fixed in:
- 4.2.3
- Disclosed:
- Jun 30, 2015
CVE-2015-5151 on NVD →
Slider Revolution [revslider] < 3.0.96
unknown
[en] The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier for Wordpress does not properly restrict access to administrator AJAX functionality, which allows remote attackers to (1) upload and execute arbitrary files via an update_plugin action; (2) dele...
- Affected:
- up to 3.0.96
- Fixed in:
- 3.0.96
- Disclosed:
- Jun 30, 2015
CVE-2014-9735 on NVD →
Slider Revolution [revslider] < 4.1.5 (unfixed)
unknown
[en] Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php. NOTE: this vulnerability may be a duplicate of CVE-2014-9734.
- Affected:
- up to 4.1.5
- Fix:
- No patched version reported
- Disclosed:
- Feb 11, 2015
CVE-2015-1579 on NVD →
WordPress Slider Revolution - Local File Disclosure
unknown
- Affected:
- up to 4.1.5
- Fixed in:
- 4.1.5
- Disclosed:
- Feb 11, 2015
CVE-2015-1579 on NVD →
Slider Revolution <= 4.1.4 - Directory Traversal
high
Directory traversal vulnerability in the Slider Revolution (revslider) plugin before 4.2 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php.
- CVSS:
- 7.5
- Affected:
- up to 4.1.4
- Fixed in:
- 4.2
- Disclosed:
- Dec 17, 2014
CVE-2014-9734 on NVD →
Slider Revolution <= 4.2.2 - Cross-Site Scripting
high
Cross-site scripting (XSS) vulnerability in the Slider Revolution (revslider) plugin 4.2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the client_action parameter in a revslider_ajax_action action to wp-admin/admin-ajax.php.
- CVSS:
- 7.2
- Affected:
- up to 4.2.2
- Fixed in:
- 4.2.3
- Disclosed:
- Dec 17, 2014
CVE-2015-5151 on NVD →
WordPress Slider Revolution Shell Upload
unknown
- Affected:
- up to 3.0.96
- Fixed in:
- 3.0.96
- Disclosed:
- Nov 30, 2014
CVE-2014-9735 on NVD →
Slider Revolution [revslider] < 3.0.96
unknown
This plugin cannot check authentication in revslider_admin.php/showbiz_admin.php which allows an attacker to abuse administrative features (for the example, creating or deleting sliders, importing or exporting sliders, etc.).
Update the plugin.
- Affected:
- up to 3.0.96
- Fixed in:
- 3.0.96
- Disclosed:
- Nov 26, 2014
Slider Revolution < 3.0.96 & Showbiz Pro < 1.7.1 - Missing Authorization to Arbitrary File Upload
critical
The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier for Wordpress does not properly restrict access to administrator AJAX functionality, which allows remote attackers to (1) upload and execute arbitrary files via an update_plugin action; (2) delete ar...
- CVSS:
- 9.8
- Affected:
- up to 3.0.96
- Fixed in:
- 3.0.96
- Disclosed:
- Nov 25, 2014
CVE-2014-9735 on NVD →
Slider Revolution [revslider] < 6.7.37
unknown
- Affected:
- up to 6.7.37
- Fixed in:
- 6.7.37
CVE-2025-9217 on NVD →