What the vulnerability does
01Description
Missing Authorization vulnerability in YITHEMES YITH Slider for page builders yith-slider-for-page-builders allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YITH Slider for page builders: from n/a through <= 1.0.11.
Explanation of Vulnerability in Simple Terms
02Summary
YITH Slider for page builders versions 1.0.11 and earlier lack proper authorization checks, allowing authenticated users to read and modify sensitive data they should not access. An attacker with a low-privilege account can view or alter slider configurations and other restricted information. Update to a version newer than 1.0.11 to resolve this issue.
What an attacker can do
03Attacker Capabilities
Read and modify slider data and settings belonging to other users or restricted areas.
Potential impact on your site
04Site Impact
Unauthorized users can access and alter slider content, potentially exposing or modifying site data.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account on the site; no special user interaction required.
Key dates
06Disclosure timeline
December 24, 2025
CVE published
April 28, 2026
Record updated