PT-2026-38255 · WordPress · Slider Revolution
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Slider Revolution versions 7.0.0 through 7.0.10
Description
Insufficient file type validation in the
get media url() and check file path() functions allows authenticated attackers with subscriber-level access or higher to perform an Arbitrary File Upload. This flaw enables the upload of executable files, which can lead to remote code execution (the ability to run arbitrary commands on the server).Recommendations
Update to version 7.0.11.
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Slider Revolution