PT-2026-20278 · WordPress · Slider Future

Zast.Ai

·

Published

2026-02-17

·

Updated

2026-03-09

·

CVE-2026-1405

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Slider Future versions up to and including 1.0.5
Description The Slider Future plugin for WordPress is susceptible to arbitrary file uploads because of a lack of file type validation within the slider future handle image upload function. This allows unauthenticated attackers to upload arbitrary files to the server, potentially leading to remote code execution.
Recommendations Deactivate the plugin immediately or apply the permission callback and extension filter patches.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2026-1405

Affected Products

Slider Future