CVE-2026-86786 PUBLISHED

Slider Pro <= 1.0.0 - Unauthenticated Sensitive Data Disclosure via sliderpro_multiple_images

Assigner: WPScan
Reserved: 08.09.2026 Published: 06.10.2026 Updated: 06.10.2026

The Slider Pro WordPress plugin through 1.0.0 does not perform any capability or authorisation check on one of its AJAX actions, allowing unauthenticated users to retrieve the title, excerpt and permalink of non-public posts, including drafts, pending, scheduled, private and trashed posts, as well as post revisions and media metadata.

Product Status

Vendor Unknown
Product Slider Pro
Versions Default: unknown
  • affected from 0 to 1.0.0 (incl.)

Credits

  • Seongwon Lee finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE