๐Ÿ” CVE Alert

CVE-2026-86786

MEDIUM 5.3

Slider Pro <= 1.0.0 - Unauthenticated Sensitive Data Disclosure via sliderpro_multiple_images

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The Slider Pro WordPress plugin through 1.0.0 does not perform any capability or authorisation check on one of its AJAX actions, allowing unauthenticated users to retrieve the title, excerpt and permalink of non-public posts, including drafts, pending, scheduled, private and trashed posts, as well as post revisions and media metadata.

Vendor unknown
Product slider pro
Published Oct 6, 2026
Last Updated Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for unknown slider pro

Be the first to know when new medium vulnerabilities affecting unknown slider pro are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Slider Pro
0 โ‰ค 1.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/0645bcad-740e-452e-9d73-3e47ddd83f8b/

Credits

Seongwon Lee WPScan