Arbitrary File Deletion Vulnerability in WP Review Slider Pro Plugin for WordPress
CVE-2026-8442
8.1HIGH
What is CVE-2026-8442?
The WP Review Slider Pro plugin for WordPress suffers from an arbitrary file deletion vulnerability due to inadequate authorization checks in its AJAX handlers. Specifically, the functions wpfb_hide_review and wprp_save_review_admin lack proper validations, enabling authenticated attackers with subscriber-level access or higher to manipulate the file system. This flaw arises from insufficient path validation, which allows potential exploitation via crafted media URLs that can lead to the deletion of arbitrary files on the server. The risk extends to remote code execution, posing a significant threat to the integrity of the affected WordPress instances.
Affected Version(s)
WP Review Slider Pro 0 <= 12.6.8