Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Slider Revolution — Vulnerabilities & Security Advisories 20

All 20 CVE vulnerabilities found in Slider Revolution, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities specific to the Slider Revolution product, a WordPress plugin developed by RevSlider. It collects known defects related to the product, focusing on weakness types such as Cross-Site Scripting (XSS) and SQL Injection, covering advisories published since 2015. Readers can use this aggregation to track the vendor’s security notices, understand the specific class of weaknesses affecting this plugin, and review the product’s historical vulnerability record without searching individual CVE databases manually. The entries provided here allow security teams to assess risk exposure and identify patterns in how this component fails to sanitize user input or handle database queries. This summary helps users quickly determine if their current version is affected by recently disclosed issues, facilitating prompt patching decisions.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2026-57678 WordPress Slider Revolution plugin 7.0.0-7.0.16 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2026-07-02
CVE-2026-7542 Slider Revolution 7.0 - 7.0.10 - Authenticated (Subscriber+) Sensitive Information Disclosure CWE-200 6.5 Medium 2026-06-09
CVE-2026-9050 Slider Revolution 6.0.0-6.7.55 and 7.0.0-7.0.14 - Missing Authorization to Authenticated (Contributor+) Arbitrary Plugin Deactivation CWE-862 4.3 Medium 2026-06-01
CVE-2026-9048 Slider Revolution 7.0.0 - 7.0.14 - Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure CWE-863 4.3 Medium 2026-06-01
CVE-2026-6728 Slider Revolution <= 7.0.9 - Unauthenticated Sensitive Information Exposure via 'sliders/stream' CWE-200 5.3 Medium 2026-05-20
CVE-2026-6692 Slider Revolution 7.0.0 - 7.0.10 - Authenticated (Subscriber+) Arbitrary File Upload via _get_media_url CWE-434 8.8 High 2026-05-07
CVE-2025-10249 Slider Revolution <= 6.7.37 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Read CWE-23 6.5 Medium 2025-10-09
CVE-2025-9217 Slider Revolution <= 6.7.36 - Authenticated (Contributor+) Arbitrary File Read via 'used_svg' and 'used_images' CWE-22 6.5 Medium 2025-08-29
CVE-2024-8107 Slider Revolution <= 6.7.18 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload CWE-79 6.4 Medium 2024-10-01
CVE-2024-37449 WordPress Slider Revolution plugin <= 6.7.13 - Cross Site Scripting (XSS) vulnerability CWE-79 5.9 Medium 2024-07-21
CVE-2024-34444 WordPress Slider Revolution plugin < 6.7.0 - Unauthenticated Broken Access Control vulnerability CWE-862 7.1 High 2024-06-19
CVE-2024-34443 WordPress Slider Revolution plugin < 6.7.11 - Cross Site Scripting (XSS) vulnerability CWE-79 5.9 Medium 2024-06-19
CVE-2024-4637 Slider Revolution <= 6.7.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Elementor wrapperid and zindex CWE-79 6.4 Medium 2024-06-04
CVE-2024-4581 Slider Revolution <= 6.7.11 - Authenticated (Author+) Stored Cross-Site Scripting via Add Layer class, id, and title Attributes CWE-79 6.4 Medium 2024-06-04
CVE-2024-4092 Slider Revolution <= 6.7.7 - Authenticated (Author+) Stored Cross-Site Scripting via htmltag Parameter CWE-79 6.4 Medium 2024-05-02
CVE-2024-2306 Revslider <= 6.6.20 - Authenticated (Author+) Stored Cross-Site Scripting CWE-79 6.4 Medium 2024-04-09
CVE-2023-6528 Slider Revolution < 6.6.19 - Author+ Insecure Deserialization leading to RCE 8.8AI High AI 2024-01-08
CVE-2023-47784 WordPress Slider Revolution Plugin <= 6.6.15 is vulnerable to Arbitrary File Upload CWE-434 8.4 High 2023-12-20
CVE-2023-47772 WordPress Slider Revolution Plugin <= 6.6.14 is vulnerable to Cross Site Scripting (XSS) CWE-79 6.5 Medium 2023-11-20
CVE-2023-2359 Revolution Slider <= 6.6.12 - Author+ Remote Code Execution 9.8 - 2023-06-19

All 20 known CVE vulnerabilities affecting Slider Revolution with full Chinese analysis, references, and POCs where available.