Authorization Bypass in Slider Pro for WordPress by Slider Revolution
CVE-2026-86786
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 6 October 2026
Badges
What is CVE-2026-86786?
The Slider Pro plugin for WordPress, up to version 1.0.0, contains a vulnerability that allows unauthenticated users to exploit an AJAX action without any capability or authorization checks. This could enable these users to access sensitive information such as the titles, excerpts, and permalinks of non-public posts. Additionally, they could retrieve details of drafts, pending, scheduled, private, and even trashed posts, including valuable post revisions and media metadata. This flaw poses a significant risk to site integrity and user privacy.
Affected Version(s)
Slider Pro 0 <= 1.0.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.