CVE · High

CVE-2023-6528 — Slider Revolution [revslider] < 6.6.19

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-6528 Slider Revolution [revslider] < 6.6.19 Improper Control of Generation of Code ('Code Injection') High 8.8 < 6.6.19 6.6.19 2023-11-30

CVE-2023-6528

The Slider Revolution plugin for WordPress contains a PHP Object Injection vulnerability affecting versions below 6.6.19 that occurs during slider import operations through unsafe deserialization of user-supplied data. Authenticated users with author privileges or higher can inject malicious PHP objects, though the plugin itself lacks an exploitable POP chain. However, if other installed plugins or themes provide a viable POP chain, attackers could potentially execute arbitrary code, exfiltrate sensitive information, or remove files from the system.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.