PT-2026-42137 · Revolution Slider · Slider Revolution

Mostafa

·

Published

2026-05-20

·

Updated

2026-05-20

·

CVE-2026-6728

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.0.9 via the 'get stream data()' function. This makes it possible for unauthenticated attackers to extract sensitive data including published password-protected post, page, and product content.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-6728

Affected Products

Slider Revolution