CVE 8.8 HIGH

Slider Revolution 7.0.0 – 7.0.10 – Authenticated (Subscriber+) Arbitrary File Upload via _get_media_url_CVE-2026-6692

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0.0 to 7.0.10 via the '_get_media_url' and '_check_file_path' function. This is due to insufficient file type validation. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible. The vulnerability was partially patched in version 7.0.10 and fully patched in version 7.0.11.

AI Analysis

Arbitrary File Upload vulnerability in Slider Revolution plugin for WordPress due to insufficient file type validation

Basic Information

ID CVE-2026-6692
Source Wordfence
Published May 7, 2026 at 04:27

Affected Product

Vendor Revolution Slider
Product Slider Revolution
Version 7.0.0
Affected Versions Revolution Slider Slider Revolution 7.0.0

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor ThemePunch
Product Slider Revolution
Version 7.0.0-7.0.10

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.