CVE · Medium

CVE-2026-7542 — Slider Revolution [revslider] < 7.0.11

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-7542 Slider Revolution [revslider] < 7.0.11 Exposure of Sensitive Information to an Unauthorized Actor Medium 6.5 < 7.0.11 7.0.11 2026-06-08

CVE-2026-7542

The Slider Revolution plugin for WordPress has a vulnerability that allows attackers to access sensitive server files. This is due to a combination of flaws that allow attackers to obtain a valid backend AJAX token, bypass access controls, and copy files from the server to a publicly accessible directory. Specifically, an attacker can use a controlled URL to copy sensitive files, such as configuration or database files, to a directory that can be accessed by anyone, including attackers with Subscriber-level access.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.