What the vulnerability does
01Description
Missing Authorization vulnerability in A WP Life Media Slider – Photo Sleder, Video Slider, Link Slider, Carousal Slideshow.This issue affects Media Slider – Photo Sleder, Video Slider, Link Slider, Carousal Slideshow: from n/a through 1.3.9.
Explanation of Vulnerability in Simple Terms
02Summary
The Media Slider plugin for WordPress contains a missing authorization flaw that allows authenticated users with low privileges to access sensitive information they should not be able to view. An attacker with a basic user account can read data that is normally restricted to higher-privilege roles. This affects versions up to 1.3.9.
What an attacker can do
03Attacker Capabilities
Read sensitive data restricted to higher-privilege users.
Potential impact on your site
04Site Impact
Unauthorized users can access private or restricted slider content and configuration data.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor).
Key dates
06Disclosure timeline
June 10, 2024
CVE published
April 28, 2026
Record updated