PT-2026-45666 · WordPress · Slider Revolution

·

CVE-2026-9048

·

Published

2026-06-01

·

Updated

2026-06-02

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Slider Revolution versions 7.0.0 through 7.0.14
Description An issue exists where authenticated attackers with Contributor-level access or higher can extract sensitive data. This is achieved via the 'slider.get.full' AJAX Action, allowing the retrieval of raw social media API credentials stored in slider settings, specifically the Instagram OAuth token, Flickr API key, YouTube Data API key, and Facebook App ID.
Recommendations Update Slider Revolution to a version later than 7.0.14. As a temporary workaround, restrict access to the 'slider.get.full' AJAX Action for users with Contributor-level permissions.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9048

Affected Products

Slider Revolution