What the vulnerability does
01Description
The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in versions less than, or equal to, 2.0.0 via the get_active_plugins function. This makes it possible for authenticated attackers, with subscriber-level access and above to extract sensitive data including installed plugin information.
Explanation of Vulnerability in Simple Terms
02Summary
bSlider versions up to 2.0.0 expose sensitive information to authenticated users. A logged-in user with low privileges can access data they should not be able to view. The vulnerability requires a valid WordPress account but no additional user interaction. Update to a version newer than 2.0.0 to resolve this issue.
What an attacker can do
03Attacker Capabilities
Read sensitive data they should not have access to as a low-privilege user.
Potential impact on your site
04Site Impact
Authenticated users can view private or restricted information, potentially exposing site data.
Conditions required to exploit
05Prerequisites
Attacker must have a valid WordPress user account with low privileges.
Key dates
06Disclosure timeline
August 15, 2025
CVE published
April 8, 2026
Record updated