PT-2026-42734 · WordPress · Slider By Soliloquy
Kitch Global
·
Published
2026-05-22
·
Updated
2026-05-22
·
CVE-2026-7636
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Slider by Soliloquy – Responsive Image Slider for WordPress versions prior to 2.8.2
Description
An issue exists where authenticated attackers with subscriber-level access or higher can extract draft slider metadata. This includes unpublished media URLs, captions, and slider configurations created by administrators or editors. The flaw is located in the
map meta cap function.Recommendations
Update to a version later than 2.8.1.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Slider By Soliloquy