{"error":0,"message":null,"data":{"name":"Slider Revolution","plugin":"revslider","link":null,"latest":null,"closed":null,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"7f5385d5a539be6f941f97eaf53a7270db044d2deeaf0735a3f738658d67d5f3","name":"Slider Revolution [revslider] < 3.0.96","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.96","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2014-9735","name":"CVE-2014-9735","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2014-9735","description":"[en] The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier for Wordpress does not properly restrict access to administrator AJAX functionality, which allows remote attackers to (1) upload and execute arbitrary files via an update_plugin action; (2) delete arbitrary sliders via a delete_slider action; and (3) create, (4) update, (5) import, or (6) export arbitrary sliders via unspecified vectors.","date":"2015-06-30"},{"id":"3e630652592c84c820bfcfa6a619a3db12385e35","name":"WordPress Slider Revolution Plugin <= 3.0.95 - Multiple Vulnerabilities","link":"https:\/\/patchstack.com\/database\/vulnerability\/slider-revolution\/wordpress-slider-revolution-plugin-3-0-95-multiple-vulnerabilities","description":"Because of these vulnerabilities, the attackers can upload and execute arbitrary files, create, update,  import or  export arbitrary sliders via unspecified vectors, also, delete arbitrary sliders.\nUpdate the plugin.","date":"2015-06-30"},{"id":"976b3cf3a3e7fe7d39b65a941b60f78dd35550b5","name":"WordPress RevSlider - File Upload and Execute","link":"https:\/\/patchstack.com\/database\/vulnerability\/slider-revolution\/wordpress-revslider-file-upload-and-execute","description":"This vulnerability allows an attacker to upload arbitrary PHP code and execute remote  code.\nUpdate the plugin.","date":"2015-05-08"},{"id":"bf6fbe1e83c18ae83d44d535e0624f0916ba25cb","name":"Slider Revolution < 3.0.96 & Showbiz Pro < 1.7.1 - Missing Authorization to Arbitrary File Upload","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/slider-revolution-3096-showbiz-pro-171-missing-authorization-to-arbitrary-file-upload","description":"The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier for Wordpress does not properly restrict access to administrator AJAX functionality, which allows remote attackers to (1) upload and execute arbitrary files via an update_plugin action; (2) delete arbitrary sliders via a delete_slider action; and (3) create, (4) update, (5) import, or (6) export arbitrary sliders via unspecified vectors. Several WordPress themes utilize revslider which makes them vulnerable as well.","date":"2014-11-25"},{"id":"973ee71bc607b3961a0ae4f3b0d36a3a976e1b9f","name":"WordPress  Slider Revolution Plugin  <= 3.0.95 is vulnerable to Remote File Inclusion","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/revslider\/vulnerability\/wordpress-revslider-file-upload-and-execute","description":"Update the plugin.\nmetasploit discovered and reported this Remote File Inclusion vulnerability in WordPress Slider Revolution Plugin. This could allow a malicious actor to get a website to load an external website or script which will then be executed on the website. This could allow the malicious actor to create backdoors on the site or take full control of the website. This vulnerability has been fixed in version 3.0.96.","date":"2023-05-08"},{"id":"124afa8617144ccda801d45279c64983665c7346","name":"WordPress  Slider Revolution Plugin  <= 3.0.95 is vulnerable to Multiple Vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/revslider\/vulnerability\/wordpress-slider-revolution-plugin-3-0-95-multiple-vulnerabilities","description":"Update the plugin.\nSimo Ben youssef discovered and reported this Multiple Vulnerabilities vulnerability in WordPress Slider Revolution Plugin. Multiple vulnerabilities were found. Due to the large number of vulnerabilities, this has been grouped in this category. This vulnerability has been fixed in version 3.0.96.","date":"2023-06-30"},{"id":"e8a8e1c6-2c43-487a-9f11-6abd5ce6d82d","name":"WordPress Slider Revolution Shell Upload","link":"https:\/\/wpscan.com\/vulnerability\/e8a8e1c6-2c43-487a-9f11-6abd5ce6d82d","description":"Note: The Construct, Echelon, Fusion, Method, Modular and Myriad affected themes are from the Mysitemyway, who went out of business, and the themes have been forked by BackStop Themes who does not use Revslider","date":null}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"}}},{"uuid":"bb8dafbd139d01a4b5199c6b4e75740a227b74084c8c42e1fbd3723f9f9dfe14","name":"Slider Revolution [revslider] < 4.2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.2.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2015-5151","name":"CVE-2015-5151","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2015-5151","description":"[en] Cross-site scripting (XSS) vulnerability in the Slider Revolution (revslider) plugin 4.2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the client_action parameter in a revslider_ajax_action action to wp-admin\/admin-ajax.php.","date":"2015-06-30"},{"id":"9ccf57b11600efd0528f39d3aa62ecf4d747aea7","name":"WordPress Slider Revolution Plugin <= 4.2.2 - XSS","link":"https:\/\/patchstack.com\/database\/vulnerability\/slider-revolution\/wordpress-slider-revolution-plugin-4-2-2-xss","description":"This vulnerability allows an attacker to inject arbitrary web script or HTML via the \"client_action\" parameter.\nUpdate the plugin.","date":"2015-06-30"},{"id":"bcfeb37437e2f1de2954f07d46dc267393dde423","name":"Slider Revolution <= 4.2.2 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/revslider\/slider-revolution-422-cross-site-scripting","description":"Cross-site scripting (XSS) vulnerability in the Slider Revolution (revslider) plugin 4.2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the client_action parameter in a revslider_ajax_action action to wp-admin\/admin-ajax.php.","date":"2014-12-17"},{"id":"5f7d4a1a519efc077876cd3acdda15a52563f1fb","name":"WordPress  Slider Revolution Plugin  <= 4.2.2 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/revslider\/vulnerability\/wordpress-slider-revolution-plugin-4-2-2-xss","description":"Update the plugin.\nindoushka  discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Slider Revolution Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 4.2.3.","date":"2023-06-30"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"1cc3ce84fd6be6e2e675517b9d3afdaf8b38a95a3d5678a4c62f1f93e738c747","name":"Slider Revolution [revslider] < 4.1.5 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.5","max_operator":"lt","unfixed":"1","closed":"0"},"source":[{"id":"CVE-2015-1579","name":"CVE-2015-1579","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2015-1579","description":"Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin\/admin-ajax.php.  NOTE: this vulnerability may be a duplicate of CVE-2014-9734.","date":"2015-02-11"},{"id":"4b077805-5dc0-4172-970e-cc3d67964f80","name":"WordPress Slider Revolution - Local File Disclosure","link":"https:\/\/wpscan.com\/vulnerability\/4b077805-5dc0-4172-970e-cc3d67964f80","description":"Note: The Construct, Echelon, Fusion, Method, Modular and Myriad affected themes are from the Mysitemyway, who went out of business, and the themes have been forked by BackStop Themes who does not use Revslider.","date":"2015-02-11"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}]}},{"uuid":"142c04a3f0ff11acee05ab9b2d4664fd22699178a83541cb43f9628b5debeba6","name":"Slider Revolution [revslider] < 3.0.96","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.96","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"04c71a6b6cb7e33ba91d6ce9ed22b69c983cea06","name":"WordPress Slider Revolution Plugin 3.0.95 - Shell Upload Exploit","link":"https:\/\/patchstack.com\/database\/vulnerability\/slider-revolution\/wordpress-slider-revolution-plugin-3-0-95-shell-upload-exploit","description":"This plugin cannot check authentication in revslider_admin.php\/showbiz_admin.php which allows an attacker to abuse administrative features (for the example, creating or deleting sliders, importing or exporting sliders, etc.).\nUpdate the plugin.","date":"2014-11-26"}],"impact":[]},{"uuid":"d998f79e6fbf2ade4697d924f7c126c190d03861759e2e1cd1fe405567b5eda7","name":"Slider Revolution [revslider] < 6.6.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.6.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-2359","name":"CVE-2023-2359","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-2359","description":"[en] The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Execution in some server configurations.","date":"2023-06-19"},{"id":"412236e618d9957fb6f43e34bcac422cf557ef2f","name":"Slider Revolution <= 6.6.12 - Authenticated (Administrator+) Arbitrary File Upload","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/revslider\/slider-revolution-6612-authenticated-administrator-arbitrary-file-upload","description":"The Slider Revolution plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in versions up to, and including, 6.6.12. This makes it possible for authenticated attackers with administrator-level attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. While the default settings allow only administrators to exploit this vulnerability, this privilege can be granted to users as low as author.","date":"2023-05-22"},{"id":"869deb7a9a7653e713b51f7450f262f4e8b45dde","name":"WordPress  Slider Revolution Plugin  <= 6.6.12 is vulnerable to Arbitrary File Upload","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/revslider\/vulnerability\/wordpress-slider-revolution-6-6-12-authenticated-arbitrary-file-upload-vulnerability","description":"Update the WordPress Slider Revolution plugin to the latest available version (at least 6.6.13).\nMarco Frison discovered and reported this Arbitrary File Upload vulnerability in WordPress Slider Revolution Plugin. This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website. This vulnerability has been fixed in version 6.6.13.","date":"2023-05-30"},{"id":"a8350890-e6d4-4b04-a158-2b0ee3748e65","name":"Revolution Slider &lt;= 6.6.12 - Author+ Remote Code Execution","link":"https:\/\/wpscan.com\/vulnerability\/a8350890-e6d4-4b04-a158-2b0ee3748e65","description":"The plugin does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Execution in some server configurations.\r\n\r\nBy default, the import functionality is only available to Admin users. However, the plugin may be configured to allow Editor and Author users to use the functionality as well.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-94","name":"Improper Control of Generation of Code ('Code Injection')","description":"The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"bf8b4895a76ffd695528c2433fcc2df874a8eb61fbebbe8c961875c56c2ba2d4","name":"Slider Revolution [revslider] < 3.0.96","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.96","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"9b9637dcb77ef7af186dee3351f8f2444be75a2d","name":"WordPress  Slider Revolution Plugin  <= 3.0.95  is vulnerable to Remote File Inclusion","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/revslider\/vulnerability\/wordpress-slider-revolution-plugin-3-0-95-shell-upload-exploit","description":"Update the plugin.\nSimo Ben Youssef discovered and reported this Remote File Inclusion vulnerability in WordPress Slider Revolution Plugin. This could allow a malicious actor to get a website to load an external website or script which will then be executed on the website. This could allow the malicious actor to create backdoors on the site or take full control of the website. This vulnerability has been fixed in version 3.0.96.","date":"2023-11-26"}],"impact":[]},{"uuid":"c5ed64fec19d4ff611b995f2a8e44e853cc338a63ed6ed69fdf9ddd5af6b482b","name":"Slider Revolution [revslider] < 6.6.16","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.6.16","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-47784","name":"CVE-2023-47784","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-47784","description":"[en] Unrestricted Upload of File with Dangerous Type vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n\/a through 6.6.15.","date":"2023-12-20"},{"id":"35276965f01010cb770acdb1b2b6d16bae3f84e9","name":"WordPress  Slider Revolution Plugin  <= 6.6.15 is vulnerable to Arbitrary File Upload","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/revslider\/vulnerability\/wordpress-slider-revolution-plugin-6-6-15-author-arbitrary-file-upload-vulnerability","description":"Update the WordPress Slider Revolution plugin to the latest available version (at least 6.6.16).\nRafie Muhammad (Patchstack) discovered and reported this Arbitrary File Upload vulnerability in WordPress Slider Revolution Plugin. This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website. This vulnerability has been fixed in version 6.6.16.","date":"2023-11-14"},{"id":"b682534055e06207f5c93018cc251cbb914a5fe7","name":"Slider Revolution <= 6.6.15 - Authenticated (Author+) Arbitrary File Upload","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/revslider\/slider-revolution-6615-authenticated-author-arbitrary-file-upload","description":"The Slider Revolution plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 6.6.15. This makes it possible for attackers with author-level access and higher to upload arbitrary files on the affected site's server which may make remote code execution possible.","date":"2023-11-14"},{"id":"1b841a64-fb0a-434f-b7b4-0777f0480c87","name":"Slider Revolution &lt; 6.6.16 - Authenticated (Author+) Arbitrary File Upload","link":"https:\/\/wpscan.com\/vulnerability\/1b841a64-fb0a-434f-b7b4-0777f0480c87","description":"The Slider Revolution plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 6.6.15. This makes it possible for attackers with author-level access and higher to upload arbitrary files on the affected site&#039;s server which may make remote code execution possible.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"h","i":"h","a":"h","score":"8.4","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:H\/I:H\/A:H","score":"8.4","severity":"high","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-434","name":"Unrestricted Upload of File with Dangerous Type","description":"The product allows the upload or transfer of dangerous file types that are automatically processed within its environment."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"1671632c8d6531d78ec7e5309ed0e6640092b5958d9198a11adfbf8f1cac3be8","name":"Slider Revolution [revslider] < 6.6.15","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.6.15","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-47772","name":"CVE-2023-47772","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-47772","description":"[en] Contributor+\u00a0Stored Cross-Site Scripting (XSS) vulnerability in Slider Revolution <=\u00a06.6.14.","date":"2023-11-20"},{"id":"3cd7b304d8931a85fbe14686344f2ec4b5670606","name":"WordPress  Slider Revolution Plugin  <= 6.6.14 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/revslider\/vulnerability\/wordpress-slider-revolution-plugin-6-6-14-cross-site-scripting-xss-vulnerability","description":"Update the WordPress Slider Revolution plugin to the latest available version (at least 6.6.15).\nRafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Slider Revolution Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 6.6.15.","date":"2023-11-14"},{"id":"d6d7873937b9e2e64409daeb5aee3c061cb132f3","name":"Slider Revolution <= 6.6.14 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/revslider\/slider-revolution-6614-authenticated-contributor-stored-cross-site-scripting","description":"The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.6.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-11-14"},{"id":"3cde24f3-aaad-4eb3-b6ba-a518afe66fbe","name":"Slider Revolution &lt; 6.6.15 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/3cde24f3-aaad-4eb3-b6ba-a518afe66fbe","description":"The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.6.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"2fbcbd46d204a00daefe9e0d7f42b4aa97ebf3f423d9a22ca43cea38e9a4269e","name":"Slider Revolution [revslider] < 6.6.19","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.6.19","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-6528","name":"CVE-2023-6528","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6528","description":"[en] The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially leading to Remote Code Execution.","date":"2024-01-08"},{"id":"36ced447-84ea-4162-80d2-6df226cb53cb","name":"Slider Revolution &lt; 6.6.19 - Author+ Insecure Deserialization leading to RCE","link":"https:\/\/wpscan.com\/vulnerability\/36ced447-84ea-4162-80d2-6df226cb53cb","description":"The plugin does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially leading to Remote Code Execution.","date":null},{"id":"cae8adfbe3c802e0660d548707bcd0036f2da0b7","name":"Slider Revolution < 6.6.19 - Authenticated (Author+) PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/revslider\/slider-revolution-6619-authenticated-author-php-object-injection","description":"The Slider Revolution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 6.6.19 (exclusive) via deserialization of untrusted input when importing a new slider. This makes it possible for authenticated attackers, with author-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.","date":"2023-11-30"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-94","name":"Improper Control of Generation of Code ('Code Injection')","description":"The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment."},{"cwe":"CWE-502","name":"Deserialization of Untrusted Data","description":"The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"a0b39bdc20312b982b1e92af79fbbe118d7c11a12a9646f5e7f44d394fb23b72","name":"Slider Revolution [revslider] < 6.7.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.7.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2306","name":"CVE-2024-2306","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2306","description":"[en] The Revslider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg upload in all versions up to, and including, 6.6.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, this can only be exploited by administrators, but the ability to use and configure revslider can be extended to authors.","date":"2024-04-09"},{"id":"9181242a6b7ed9a182412206414d950df68bae59","name":"Revslider <= 6.6.20 - Authenticated (Author+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/revslider\/revslider-6620-authenticated-author-stored-cross-site-scripting","description":"The Revslider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg upload in all versions up to, and including, 6.6.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, this can only be exploited by administrators, but the ability to use and configure revslider can be extended to authors.","date":"2024-04-08"},{"id":"4ba1030a72968adf4da52f99b1a0679e6c39c2cb","name":"WordPress  Slider Revolution Plugin    <= 6.6.20 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/revslider\/vulnerability\/wordpress-revslider-plugin-6-6-20-authenticated-author-stored-cross-site-scripting-vulnerability","description":"Update the WordPress Slider Revolution plugin to the latest available version (at least 6.7.0).\nwesley (wcraft) , Nikolas - mdr discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Slider Revolution Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 6.7.0.\nHave additional information or questions about this entry? Get in touch.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-80","name":"Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)","description":"The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as \"<\", \">\", and \"&\" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"90fa9ab1c588fdef488678a469000fc46619dc49ee2c67fe06fd34539806d805","name":"Slider Revolution [revslider] < 6.7.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.7.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-4092","name":"CVE-2024-4092","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-4092","description":"[en] The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018htmltag\u2019 parameter in all versions up to, and including, 6.7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, this can only be exploited by administrators, but the ability to use and configure Slider Revolution can be extended to authors.","date":"2024-05-02"},{"id":"82229efbd9ff70b09969395704dc9845fc564433","name":"Slider Revolution <= 6.7.7 - Authenticated (Author+) Stored Cross-Site Scripting via htmltag Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/revslider\/slider-revolution-677-authenticated-author-stored-cross-site-scripting-via-htmltag-parameter","description":"The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018htmltag\u2019 parameter in all versions up to, and including, 6.7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, this can only be exploited by administrators, but the ability to use and configure Slider Revolution can be extended to authors.","date":"2024-04-30"},{"id":"c899760057a099739452e860f2203d51909bb380","name":"WordPress Slider Revolution Plugin <= 6.7.7 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/revslider\/vulnerability\/wordpress-slider-revolution-plugin-6-7-7-authenticated-author-stored-cross-site-scripting-via-htmltag-parameter-vulnerability","description":"<p>WordPress Slider Revolution Plugin <= 6.7.7 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Affected Version <= 6.7.7<\/p><p>Fixed in version 6.7.8 <\/p>","date":"2024-05-01"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"562990c0d50b2cf5297b4966155ab8b25c24e0c46585c4438388616c69cc86a7","name":"Slider Revolution [revslider] < 6.7.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.7.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-34444","name":"CVE-2024-34444","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-34444","description":"[en] Missing Authorization vulnerability in ThemePunch OHG Slider Revolution revslider.This issue affects Slider Revolution: from n\/a through < 6.7.0.","date":"2024-06-19"},{"id":"b0f13cbaaab990cd88a415ec7299846a0d58eb1f","name":"WordPress Slider Revolution Plugin < 6.7.0 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/revslider\/vulnerability\/wordpress-slider-revolution-plugin-6-7-0-unauthenticated-broken-access-control-vulnerability","description":"<p>WordPress Slider Revolution Plugin < 6.7.0 is vulnerable to Broken Access Control<\/p><p>Affected Version < 6.7.0<\/p><p>Fixed in version 6.7.0 <\/p>","date":"2024-05-28"},{"id":"f230d2715f3118d5702df2cdff4750b6bd62e879","name":"Slider Revolution <= 6.6.20 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/revslider\/slider-revolution-6620-missing-authorization","description":"The Slider Revolution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init_rest_api function in versions up to 6.7.0. This makes it possible for unauthenticated attackers to update slider data.","date":"2024-05-28"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"7.1","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"7.1","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"18d22e7aa0d58a741f7530f5038806cc3adb28973242a5c3d1163959299a2e27","name":"Slider Revolution [revslider] < 6.7.11","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.7.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-34443","name":"CVE-2024-34443","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-34443","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemePunch OHG Slider Revolution revslider.This issue affects Slider Revolution: from n\/a through < 6.7.11.","date":"2024-06-19"},{"id":"88e9cc99f7774841dbd4b8f773ea1c3c11967d18","name":"WordPress Slider Revolution Plugin < 6.7.11 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/revslider\/vulnerability\/wordpress-slider-revolution-plugin-6-7-11-cross-site-scripting-xss-vulnerability","description":"<p>WordPress Slider Revolution Plugin < 6.7.11 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Affected Version < 6.7.11<\/p><p>Fixed in version 6.7.11 <\/p>","date":"2024-05-28"},{"id":"16337d30af091e66ba4172ef9d58a3755dc38250","name":"Slider Revolution <= 6.7.10 - Authenticated (Author+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/revslider\/slider-revolution-6710-authenticated-author-stored-cross-site-scripting","description":"The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.7.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-28"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"5.9","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"5.9","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"67d1569e7198bdfbf7c57327987ff84151061bff21e87c07e6a3d73a6b8fc910","name":"Slider Revolution [revslider] < 6.7.11","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.7.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-4581","name":"CVE-2024-4581","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-4581","description":"[en] The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Add Layer widget in all versions up to, and including, 6.7.11 due to insufficient input sanitization and output escaping on the user supplied 'class', 'id', and 'title' attributes. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: Successful exploitation of this vulnerability requires an Administrator to give Slider Creation privileges to Author-level users.","date":"2024-06-04"},{"id":"a9ab6bf4d5c36d87511e839c0614f6fe718d06c8","name":"Slider Revolution <= 6.7.11 - Authenticated (Author+) Stored Cross-Site Scripting via Add Layer class, id, and title Attributes","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/revslider\/slider-revolution-6711-authenticated-author-stored-cross-site-scripting-via-add-layer-class-id-and-title-attributes","description":"The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Add Layer widget in all versions up to, and including, 6.7.11 due to insufficient input sanitization and output escaping on the user supplied 'class', 'id', and 'title' attributes. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: Successful exploitation of this vulnerability requires an Administrator to give Slider Creation privileges to Author-level users.","date":"2024-06-03"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"7cec5c47306dce8a80694fc269a542c4a970d4009440c7482636d963e06bbef0","name":"Slider Revolution [revslider] < 6.7.11","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.7.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-4637","name":"CVE-2024-4637","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-4637","description":"[en] The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.7.10 due to insufficient input sanitization and output escaping on the user supplied Elementor 'wrapperid' and 'zindex' display attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-06-04"},{"id":"d11681970344c824e10c12f109547c3a6e3133b8","name":"Slider Revolution <= 6.7.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Elementor wrapperid and zindex","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/revslider\/slider-revolution-6710-authenticated-contributor-stored-cross-site-scripting-via-elementor-wrapperid-and-zindex","description":"The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.7.10 due to insufficient input sanitization and output escaping on the user supplied Elementor 'wrapperid' and 'zindex' display attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-06-03"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"ded26d71fd89f11da336e97fa098b81d525cbe68975bf60a75b871a336f3c2fa","name":"Slider Revolution [revslider] < 6.7.14","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.7.14","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-37449","name":"CVE-2024-37449","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-37449","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemePunch OHG Slider Revolution revslider.This issue affects Slider Revolution: from n\/a through <= 6.7.13.","date":"2024-07-21"},{"id":"094c6a8523aea08db8e7dfb4237b1a1c4fbb42a3","name":"WordPress Slider Revolution Plugin <= 6.7.13 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/revslider\/vulnerability\/wordpress-slider-revolution-plugin-6-7-13-cross-site-scripting-xss-vulnerability","description":"<p>WordPress Slider Revolution Plugin <= 6.7.13 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Affected Version <= 6.7.13<\/p><p>Fixed in version 6.7.14 <\/p>","date":"2024-06-28"},{"id":"e75eeb4e3a60a95e3c97d3ec9d1ef29922814dbf","name":"Slider Revolution <= 6.7.13 - Authenticated (Administrator+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/revslider\/slider-revolution-6713-authenticated-administrator-stored-cross-site-scripting","description":"The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.7.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only impacts multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-06-28"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"5.9","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"5.9","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"b28907036c76bc2865e9e63edb9e1bde8c581aca3299c7cb569d0bc8d9673c02","name":"Slider Revolution [revslider] < 6.7.19","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.7.19","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-8107","name":"CVE-2024-8107","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-8107","description":"[en] The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. By default, this can only be exploited by administrators, but the ability to use and configure Slider Revolution can be extended to authors.","date":"2024-10-01"},{"id":"88582a84b35bf685190a33b30cb706998246486e","name":"WordPress Slider Revolution Plugin <= 6.7.18 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/revslider\/vulnerability\/wordpress-slider-revolution-plugin-6-7-18-authenticated-author-stored-cross-site-scripting-via-svg-file-upload-vulnerability","description":"<p>WordPress Slider Revolution Plugin <= 6.7.18 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Affected Version <= 6.7.18<\/p><p>Fixed in version 6.7.19 <\/p>","date":"2024-10-01"},{"id":"b81e7f298e6dc6ce01624a8eb9791c57f1edb475","name":"Slider Revolution <= 6.7.18 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/revslider\/slider-revolution-6718-authenticated-author-stored-cross-site-scripting-via-svg-file-upload","description":"The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. By default, this can only be exploited by administrators, but the ability to use and configure Slider Revolution can be extended to authors.","date":"2024-09-30"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"d7509cea2ee66a18c9fcb28dbad97c789651227a5a745d2e00247ac882ce0d24","name":"Slider Revolution [revslider] < 6.7.37","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.7.37","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-9217","name":"Slider Revolution <= 6.7.36 - Authenticated (Contributor+) Arbitrary File Read via 'used_svg' and 'used_images'","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-9217","description":"The Slider Revolution plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.7.36 via the 'used_svg' and 'used_images' parameters. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.","date":"0000-00-00"},{"id":"70bc59fe326288e3ea67521e83b5dd7734fa10a5","name":"WordPress Slider Revolution Plugin <= 6.7.36 is vulnerable to Arbitrary File Download","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/revslider\/vulnerability\/wordpress-slider-revolution-plugin-6-7-36-authenticated-contributor-arbitrary-file-read-via-used-svg-and-used-images-vulnerability","description":"<p>WordPress Slider Revolution Plugin <= 6.7.36 is vulnerable to Arbitrary File Download<\/p><p>Software: Slider Revolution<\/p><p>Fixed in version 6.7.37 <\/p><p>Affected Version <= 6.7.36<\/p><p>CVE: CVE-2025-9217<\/p>","date":"2025-08-29"},{"id":"3eb089780560e6443a5ba3699fc85d20554801e1","name":"Slider Revolution <= 6.7.36 - Authenticated (Contributor+) Arbitrary File Read via 'used_svg' and 'used_images'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/revslider\/slider-revolution-6736-authenticated-contributor-arbitrary-file-read-via-used-svg-and-used-images","description":"The Slider Revolution plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.7.36 via the 'used_svg' and 'used_images' parameters. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.","date":"2025-08-28"},{"id":"EUVD-2025-26172","name":"EUVD-2025-26172","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-26172","description":"The Slider Revolution plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.7.36 via the 'used_svg' and 'used_images' parameters. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.","date":"2025-08-29"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"6.5","severity":"m","exploitable":"2.8","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"2.8","impact":"3.6"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"015b5cca4431c2503d549faea309adbc9918dd09c221e15d201b3e7246c7cc8a","name":"Slider Revolution [revslider] < 6.7.38","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.7.38","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-10249","name":"CVE-2025-10249","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-10249","description":"[en] The Slider Revolution plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions in all versions up to, and including, 6.7.37. This makes it possible for authenticated attackers, with Contributor-level access and above, to install and activate plugin add-ons, create sliders, and download arbitrary files.","date":"2025-10-09"},{"id":"589f07ae2525929e9d946b79934a5091c253bd89","name":"Slider Revolution <= 6.7.37 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Read","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/revslider\/slider-revolution-6737-missing-authorization-to-authenticated-contributor-arbitrary-file-read","description":"The Slider Revolution plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions in all versions up to, and including, 6.7.37. This makes it possible for authenticated attackers, with Contributor-level access and above, to install and activate plugin add-ons, create sliders, and download arbitrary files.","date":"2025-10-08"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"6.5","severity":"m","exploitable":"2.8","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"2.8","impact":"3.6"},"cwe":[{"cwe":"CWE-23","name":"Relative Path Traversal","description":"The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as \"..\" that can resolve to a location that is outside of that directory."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"463208b2c9bf79da036b95120bad0d72840a339bd725128f0b29941345221ed3","name":"Slider Revolution [revslider] >= 7.0.0 - < 7.0.11","description":null,"operator":{"min_version":"7.0.0","min_operator":"ge","max_version":"7.0.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-6692","name":"CVE-2026-6692","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-6692","description":"[en] The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0.0 to 7.0.10 via the '_get_media_url' and '_check_file_path' function. This is due to insufficient file type validation. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible. The vulnerability was partially patched in version 7.0.10 and fully patched in version 7.0.11.","date":"2026-05-07"},{"id":"964ff4dd00fbe15ab0bf9677b5e0186e46035fbb","name":"Slider Revolution 7.0.0 - 7.0.10 - Authenticated (Subscriber+) Arbitrary File Upload via _get_media_url","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/revslider\/slider-revolution-700-7010-authenticated-subscriber-arbitrary-file-upload-via-get-media-url","description":"The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0.0 to 7.0.10 via the '_get_media_url' and '_check_file_path' function. This is due to insufficient file type validation. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible. The vulnerability was partially patched in version 7.0.10 and fully patched in version 7.0.11.","date":"2026-05-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-434","name":"Unrestricted Upload of File with Dangerous Type","description":"The product allows the upload or transfer of dangerous file types that are automatically processed within its environment."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"a010702404aafb5f8b64054d81859fe6806b268fcd08d82b7feb3052da3833f4","name":"Slider Revolution [revslider] < 7.0.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.0.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-6728","name":"CVE-2026-6728","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-6728","description":"[en] The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.0.9 via the 'get_stream_data()' function. This makes it possible for unauthenticated attackers to extract sensitive data including published password-protected post, page, and product content.","date":"2026-05-20"},{"id":"3a97fcd2c1d63d1bfd5f3cf36f5771ea530961ea","name":"Slider Revolution <= 7.0.9 - Unauthenticated Sensitive Information Exposure via 'sliders\/stream'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/revslider\/slider-revolution-709-unauthenticated-sensitive-information-exposure-via-slidersstream","description":"The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.0.9 via the 'get_stream_data()' function. This makes it possible for unauthenticated attackers to extract sensitive data including published password-protected post, page, and product content.","date":"2026-05-19"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"b57c74afe3f622d9035340daf80114834b85ddf1a109225188d5d7abb79b4f71","name":"Slider Revolution [revslider] < 6.7.56","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.7.56","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-9050","name":"CVE-2026-9050","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-9050","description":"[en] The Slider Revolution plugin for WordPress in versions 6.0.0-6.7.55 and 7.0.0-7.0.14 is vulnerable to unauthorized modification of data. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Contributor-level access and above, to deactivate any active plugin installed on the site.","date":"2026-06-01"},{"id":"2f3c80b9b021fd4bfdc3757849f9c5d76751c3f7","name":"Slider Revolution 6.0.0-6.7.55 and 7.0.0-7.0.14 - Missing Authorization to Authenticated (Contributor+) Arbitrary Plugin Deactivation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/revslider\/slider-revolution-600-6755-and-700-7014-missing-authorization-to-authenticated-contributor-arbitrary-plugin-deactivation","description":"The Slider Revolution plugin for WordPress in versions 6.0.0-6.7.55 and 7.0.0-7.0.14 is vulnerable to unauthorized modification of data. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Contributor-level access and above, to deactivate any active plugin installed on the site.","date":"2026-06-01"},{"id":"EUVD-2026-33850","name":"EUVD-2026-33850","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-33850","description":"The Slider Revolution plugin for WordPress in versions 6.0.0-6.7.55 and 7.0.0-7.0.14 is vulnerable to unauthorized modification of data. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Contributor-level access and above, to deactivate any active plugin installed on the site.","date":"2026-06-01"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"ddda29ca90e951c38ba9be751f9f77978e90dd3dc282b40fe6c4ae3408a29f32","name":"Slider Revolution [revslider] < 7.0.15","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.0.15","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-9048","name":"CVE-2026-9048","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-9048","description":"[en] The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 7.0.0 - 7.0.14, via the 'slider.get.full' AJAX Action. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including raw social media API credentials: the Instagram OAuth token, Flickr API key, YouTube Data API key, and Facebook App ID, stored in any configured slider's settings.","date":"2026-06-01"},{"id":"9b4ec2ed82ed9e1c7552abad8a7157a48f4ceca7","name":"Slider Revolution 7.0.0 - 7.0.14 - Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/revslider\/slider-revolution-700-7014-incorrect-authorization-to-authenticated-contributor-sensitive-information-exposure","description":"The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 7.0.0 - 7.0.14, via the 'slider.get.full' AJAX Action. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including raw social media API credentials: the Instagram OAuth token, Flickr API key, YouTube Data API key, and Facebook App ID, stored in any configured slider's settings.","date":"2026-06-01"},{"id":"EUVD-2026-33851","name":"EUVD-2026-33851","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-33851","description":"The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 7.0.0 - 7.0.14, via the 'slider.get.full' AJAX Action. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including raw social media API credentials: the Instagram OAuth token, Flickr API key, YouTube Data API key, and Facebook App ID, stored in any configured slider's settings.","date":"2026-06-01"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"4.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-863","name":"Incorrect Authorization","description":"The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"32f8a2aca281a1359e7aa700c0b93abe70c685dc8b54300dbbcabe16d52c39d6","name":"Slider Revolution [revslider] < 7.0.11","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.0.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-7542","name":"CVE-2026-7542","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-7542","description":"[en] The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions 7.0 to 7.0.10. This is due to three compounding design flaws: (1) the plugin leaks a valid backend AJAX nonce (revslider_actions) to all authenticated users including Subscribers via the admin_footer hook; (2) the wordpress.create.image_from_url action is explicitly allowlisted in the $user_allowed array, bypassing the administrator-only access control; (3) the create_wordpress_image_from_url() function accepts an attacker-controlled url parameter that is passed to import_media(), where path_or_url_exists() explicitly accepts local filesystem paths (file_exists() && is_readable()) with no restriction to remote HTTP\/HTTPS URLs, and @copy() physically copies those files into the publicly accessible \/wp-content\/uploads\/revslider\/ai\/ directory. The MIME type check trusts the attacker-supplied content_type parameter to derive the destination extension without verifying actual file content, and the source extension blacklist does not block many sensitive types (.sql, .log, .json, .bak, .xml, .csv, .conf, .yml, .yaml, .pem, .key, .crt, .txt, .db, etc.). This makes it possible for authenticated attackers with Subscriber-level access and above to read the contents of server files with non-blacklisted extensions by having them copied to a publicly accessible URL.","date":"2026-06-09"},{"id":"42335adfbb586725824fc43d7a8f253aad89b931","name":"Slider Revolution 7.0 - 7.0.10 - Authenticated (Subscriber+) Sensitive Information Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/revslider\/slider-revolution-7010-authenticated-subscriber-sensitive-information-disclosure","description":"The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions 7.0 to 7.0.10. This is due to three compounding design flaws: (1) the plugin leaks a valid backend AJAX nonce (revslider_actions) to all authenticated users including Subscribers via the admin_footer hook; (2) the wordpress.create.image_from_url action is explicitly allowlisted in the $user_allowed array, bypassing the administrator-only access control; (3) the create_wordpress_image_from_url() function accepts an attacker-controlled url parameter that is passed to import_media(), where path_or_url_exists() explicitly accepts local filesystem paths (file_exists() && is_readable()) with no restriction to remote HTTP\/HTTPS URLs, and @copy() physically copies those files into the publicly accessible \/wp-content\/uploads\/revslider\/ai\/ directory. The MIME type check trusts the attacker-supplied content_type parameter to derive the destination extension without verifying actual file content, and the source extension blacklist does not block many sensitive types (.sql, .log, .json, .bak, .xml, .csv, .conf, .yml, .yaml, .pem, .key, .crt, .txt, .db, etc.). This makes it possible for authenticated attackers with Subscriber-level access and above to read the contents of server files with non-blacklisted extensions by having them copied to a publicly accessible URL.","date":"2026-06-08"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"6.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"664da6daae3fea3e1c32791a52f9d23482a4d9f22cb2d2acce7865b00e784936","name":"Slider Revolution [revslider] < 7.1.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.1.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-57678","name":"CVE-2026-57678","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-57678","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemePunch Slider Revolution allows Reflected XSS.\n\nThis issue affects Slider Revolution: from 7.0.0 through 7.0.16.","date":"2026-07-02"},{"id":"b85806eb550df1272988bc3a49848e5d8ce5b100","name":"Slider Revolution  7.0.0-7.0.16 - Unauthenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/revslider\/slider-revolution-700-7016-unauthenticated-stored-cross-site-scripting","description":"The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 7.0.0-7.0.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-06-30"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"7.1","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"7.1","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1789970321"}