Slider Future WordPress plugin <= 1.0.5 contains an unrestricted file upload vulnerability caused by missing file type validation in 'slider_future_handle_image_upload', letting unauthenticated attackers upload arbitrary files, exploit requires no authentication.
id: CVE-2026-1405
info:
name: WordPress Slider Future <= 1.0.5 - Unauthenticated Arbitrary File U
...