Sensitive Information Exposure in Slider Revolution Plugin for WordPress
CVE-2026-9048

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 June 2026

What is CVE-2026-9048?

The Slider Revolution plugin for WordPress contains a vulnerability that allows authenticated users with Contributor-level access and above to exploit the 'slider.get.full' AJAX Action. This flaw can lead to the unauthorized extraction of sensitive information, including critical social media API credentials, such as Instagram OAuth tokens, Flickr API keys, YouTube Data API keys, and Facebook App IDs, which are stored in the settings of any configured slider. This exposure poses a significant risk to site owners who utilize the plugin, potentially leading to data breaches and unauthorized access to their social media accounts.

Affected Version(s)

Slider Revolution 7.0.0 <= 7.0.14

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Prickly Cactus
.