What the vulnerability does
01Description
The Slider Revolution plugin for WordPress in versions 6.0.0-6.7.55 and 7.0.0-7.0.14 is vulnerable to unauthorized modification of data. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Contributor-level access and above, to deactivate any active plugin installed on the site.
Explanation of Vulnerability in Simple Terms
02Summary
Slider Revolution versions 6.0.0 through 6.7.55 lack proper authorization checks, allowing authenticated users to modify content they should not have access to. An attacker with low-level site access can alter slider data without proper permission validation. Update to a version newer than 6.7.55 to resolve this issue.
What an attacker can do
03Attacker Capabilities
Modify slider content and settings without proper authorization.
Potential impact on your site
04Site Impact
Unauthorized users can alter sliders, potentially defacing content or disrupting site appearance.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege account on the site (e.g., subscriber or contributor role).
Key dates
06Disclosure timeline
June 1, 2026
CVE published
June 2, 2026
Record updated