The Slider Revolution plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions in all versions up to, and including, 6.7.37. This makes it possible for authenticated attackers, with Contributor-level access and above, to install and activate plugin add-ons, create sliders, and download arbitrary files.
Metrics
Affected Vendors & Products
References
History
Fri, 10 Oct 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Revolution Slider
Revolution Slider slider Revolution Wordpress Wordpress wordpress |
|
| Vendors & Products |
Revolution Slider
Revolution Slider slider Revolution Wordpress Wordpress wordpress |
Thu, 09 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 09 Oct 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Slider Revolution plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions in all versions up to, and including, 6.7.37. This makes it possible for authenticated attackers, with Contributor-level access and above, to install and activate plugin add-ons, create sliders, and download arbitrary files. | |
| Title | Slider Revolution <= 6.7.37 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Read | |
| Weaknesses | CWE-23 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-10-09T11:20:56.306Z
Updated: 2025-10-09T14:46:37.151Z
Reserved: 2025-09-10T21:30:22.983Z
Link: CVE-2025-10249
Updated: 2025-10-09T14:46:34.152Z
Status : Awaiting Analysis
Published: 2025-10-09T12:15:34.873
Modified: 2025-10-09T15:50:04.013
Link: CVE-2025-10249
No data.