Extension WordPress
Vulnérabilités Slider Revolution
Cette page rassemble les failles publiées pour Slider Revolution, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Slider Revolution
23 fiches
Slider Revolution 7.0.0-7.0.16 – Unauthenticated Stored Cross-Site Scripting
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 7.0.0-7.0.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
7.0.0-7.0.16
7.1.0
30/06/2026
Slider Revolution 7.0 – 7.0.10 – Authenticated (Subscriber+) Sensitive Information Disclosure
The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions 7.0 to 7.0.10. This is due to three compounding design flaws: (1) the plugin leaks a valid backend AJAX nonce (revslider_actions) to all authenticated…
7.0-7.0.10
7.0.11
08/06/2026
Slider Revolution 6.0.0-6.7.55 and 7.0.0-7.0.14 – Missing Authorization to Authenticated (Contributor+) Arbitrary Plugin Deactivation
The Slider Revolution plugin for WordPress in versions 6.0.0-6.7.55 and 7.0.0-7.0.14 is vulnerable to unauthorized modification of data. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes…
6.0.0-6.7.55, 7.0.0-7.0.14
6.7.56, 7.0.15
01/06/2026
Slider Revolution 7.0.0 – 7.0.14 – Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure
The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 7.0.0 – 7.0.14, via the 'slider.get.full' AJAX Action. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data…
7.0.0-7.0.14
7.0.15
01/06/2026
Slider Revolution <= 7.0.9 – Unauthenticated Sensitive Information Exposure via 'sliders/stream'
The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.0.9 via the 'get_stream_data()' function. This makes it possible for unauthenticated attackers to extract sensitive data including published password-protected post,…
6.0-6.7.54, 7.0-7.0.9
6.7.55, 7.0.10
19/05/2026
Slider Revolution 7.0.0 – 7.0.10 – Authenticated (Subscriber+) Arbitrary File Upload via _get_media_url
The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0.0 to 7.0.10 via the '_get_media_url' and '_check_file_path' function. This is due to insufficient file type validation. This makes it possible for authenticated attackers,…
7.0.0-7.0.10
7.0.11
06/05/2026
Slider Revolution <= 6.7.37 – Missing Authorization to Authenticated (Contributor+) Arbitrary File Read
The Slider Revolution plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions in all versions up to, and including, 6.7.37. This makes it possible for authenticated…
*-6.7.37
6.7.38
08/10/2025
Slider Revolution <= 6.7.36 – Authenticated (Contributor+) Arbitrary File Read via 'used_svg' and 'used_images'
The Slider Revolution plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.7.36 via the 'used_svg' and 'used_images' parameters. This makes it possible for authenticated attackers, with Contributor-level access and above, to…
*-6.7.36
6.7.37
28/08/2025
Slider Revolution <= 6.7.18 – Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-6.7.18
6.7.19
30/09/2024
Slider Revolution <= 6.7.13 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.7.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and…
*-6.7.13
6.7.14
28/06/2024
Slider Revolution <= 6.7.10 – Authenticated (Contributor+) Stored Cross-Site Scripting via Elementor wrapperid and zindex
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.7.10 due to insufficient input sanitization and output escaping on the user supplied Elementor 'wrapperid' and 'zindex' display attributes.…
*-6.7.10
6.7.11
03/06/2024
Slider Revolution <= 6.7.11 – Authenticated (Author+) Stored Cross-Site Scripting via Add Layer class, id, and title Attributes
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Add Layer widget in all versions up to, and including, 6.7.11 due to insufficient input sanitization and output escaping on the user supplied…
*-6.7.10
6.7.11
03/06/2024
Slider Revolution <= 6.6.20 – Missing Authorization
The Slider Revolution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init_rest_api function in versions up to 6.7.0. This makes it possible for unauthenticated attackers to update slider…
*-6.6.20
6.7.0
28/05/2024
Slider Revolution <= 6.7.10 – Authenticated (Author+) Stored Cross-Site Scripting
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.7.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access…
*-6.7.10
6.7.11
28/05/2024
Slider Revolution <= 6.7.7 – Authenticated (Author+) Stored Cross-Site Scripting via htmltag Parameter
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘htmltag’ parameter in all versions up to, and including, 6.7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-6.7.7
6.7.8
30/04/2024
Revslider <= 6.6.20 – Authenticated (Author+) Stored Cross-Site Scripting
The Revslider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg upload in all versions up to, and including, 6.6.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to…
*-6.6.20
6.7.0
08/04/2024
Slider Revolution < 6.6.19 – Authenticated (Author+) PHP Object Injection
The Slider Revolution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 6.6.19 (exclusive) via deserialization of untrusted input when importing a new slider. This makes it possible for authenticated attackers, with author-level…
[*, 6.6.19)
6.6.19
30/11/2023
Slider Revolution <= 6.6.15 – Authenticated (Author+) Arbitrary File Upload
The Slider Revolution plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 6.6.15. This makes it possible for attackers with author-level access and higher to upload arbitrary files on the affected…
*-6.6.15
6.6.16
14/11/2023
Slider Revolution <= 6.6.14 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.6.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-6.6.14
6.6.15
14/11/2023
Slider Revolution <= 6.6.12 – Authenticated (Administrator+) Arbitrary File Upload
The Slider Revolution plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in versions up to, and including, 6.6.12. This makes it possible for authenticated attackers with administrator-level attackers to upload arbitrary…
*-6.6.12
6.6.13
22/05/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.