Arbitrary File Deletion Vulnerability in WP Review Slider Pro Plugin for WordPress
CVE-2026-8442

8.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 June 2026

What is CVE-2026-8442?

The WP Review Slider Pro plugin for WordPress suffers from an arbitrary file deletion vulnerability due to inadequate authorization checks in its AJAX handlers. Specifically, the functions wpfb_hide_review and wprp_save_review_admin lack proper validations, enabling authenticated attackers with subscriber-level access or higher to manipulate the file system. This flaw arises from insufficient path validation, which allows potential exploitation via crafted media URLs that can lead to the deletion of arbitrary files on the server. The risk extends to remote code execution, posing a significant threat to the integrity of the affected WordPress instances.

Affected Version(s)

WP Review Slider Pro 0 <= 12.6.8

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

PhĂş
.