Sensitive Information Exposure in Slider Revolution Plugin for WordPress
CVE-2026-9048
4.3MEDIUM
What is CVE-2026-9048?
The Slider Revolution plugin for WordPress contains a vulnerability that allows authenticated users with Contributor-level access and above to exploit the 'slider.get.full' AJAX Action. This flaw can lead to the unauthorized extraction of sensitive information, including critical social media API credentials, such as Instagram OAuth tokens, Flickr API keys, YouTube Data API keys, and Facebook App IDs, which are stored in the settings of any configured slider. This exposure poses a significant risk to site owners who utilize the plugin, potentially leading to data breaches and unauthorized access to their social media accounts.
Affected Version(s)
Slider Revolution 7.0.0 <= 7.0.14