CVE-2026-7542
The Slider Revolution plugin for WordPress has a vulnerability that allows attackers to access sensitive server files. This is due to a combination of flaws that allow attackers to obtain a valid backend AJAX token, bypass access controls, and copy files from the server to a publicly accessible directory. Specifically, an attacker can use a controlled URL to copy sensitive files, such as configuration or database files, to a directory that can be accessed by anyone, including attackers with Subscriber-level access.
Based on public CVE data (MITRE/NVD).