Description
The Slider Revolution plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions in all versions up to, and including, 6.7.37. This makes it possible for authenticated attackers, with Contributor-level access and above, to install and activate plugin add-ons, create sliders, and download arbitrary files.
Problem types
CWE-23 Relative Path Traversal
Product status
*
Timeline
2025-09-10: | Vendor Notified |
2025-10-08: | Disclosed |
Credits
Matthew Rollings
References
www.wordfence.com/...-c19d-4b7c-849b-47052bb62cb5?source=cve
www.sliderrevolution.com/documentation/changelog/