SQL Injection Flaw in 10Web Slider Plugin
CVE-2026-42710

7.6HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
7 October 2026

What is CVE-2026-42710?

The 10Web Slider plugin for WordPress is susceptible to an SQL injection vulnerability, specifically a Blind SQL Injection flaw. This vulnerability allows attackers to manipulate SQL queries by injecting malicious input, potentially compromising the database's confidentiality and integrity. The affected versions include those up to and including 1.2.63, making it crucial for users to update to the latest version to mitigate risks associated with this security flaw. Immediate action is recommended to ensure the security of websites utilizing this plugin.

Affected Version(s)

Slider by 10Web 0 <= 1.2.63

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack)
.