WP Clinic
Log in Sign up

CVE · Medium

CVE-2025-10249 — Slider Revolution [revslider] < 6.7.38

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-10249 Slider Revolution [revslider] < 6.7.38 Relative Path Traversal Medium 6.5 < 6.7.38 6.7.38 2025-10-08

CVE-2025-10249

The Slider Revolution plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions in all versions up to, and including, 6.7.37. This makes it possible for authenticated attackers, with Contributor-level access and above, to install and activate plugin add-ons, create sliders, and download arbitrary files.

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.