Slider Revolution

Explore Slider Revolution vulnerabilities across all versions. Currently tracking 23 known vulnerabilities, including severity, impact, and patch status.

01234567891025.11.2014Today25.11.20149.8Slider Revolution < 3.0.96 & Showbiz Pro < 1.7.1 - Missing Authorization to Arbitrary File Upload CVSS 9.8 · 25.11.201417.12.20147.5Slider Revolution <= 4.1.4 - Directory Traversal CVSS 7.5 · 17.12.20147.2Slider Revolution <= 4.2.2 - Cross-Site Scripting CVSS 7.2 · 17.12.201422.05.20237.2Slider Revolution <= 6.6.12 - Authenticated (Administrator+) Arbitrary File Upload CVSS 7.2 · 22.05.202314.11.20236.4Slider Revolution <= 6.6.14 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 14.11.20237.2Slider Revolution <= 6.6.15 - Authenticated (Author+) Arbitrary File Upload CVSS 7.2 · 14.11.202330.11.20238.8Slider Revolution < 6.6.19 - Authenticated (Author+) PHP Object Injection CVSS 8.8 · 30.11.202308.04.20246.4Revslider <= 6.6.20 - Authenticated (Author+) Stored Cross-Site Scripting CVSS 6.4 · 08.04.202430.04.20246.4Slider Revolution <= 6.7.7 - Authenticated (Author+) Stored Cross-Site Scripting via htmltag Parameter CVSS 6.4 · 30.04.202428.05.20246.4Slider Revolution <= 6.7.10 - Authenticated (Author+) Stored Cross-Site Scripting CVSS 6.4 · 28.05.20246.4Slider Revolution <= 6.6.20 - Missing Authorization CVSS 6.4 · 28.05.202403.06.20246.4Slider Revolution <= 6.7.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Elementor wrapperid and zindex CVSS 6.4 · 03.06.20246.4Slider Revolution <= 6.7.11 - Authenticated (Author+) Stored Cross-Site Scripting via Add Layer class, id, and title Attributes CVSS 6.4 · 03.06.202428.06.20244.4Slider Revolution <= 6.7.13 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 28.06.202430.09.20246.4Slider Revolution <= 6.7.18 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload CVSS 6.4 · 30.09.202428.08.20256.5Slider Revolution <= 6.7.36 - Authenticated (Contributor+) Arbitrary File Read via 'used_svg' and 'used_images' CVSS 6.5 · 28.08.202508.10.20256.5Slider Revolution <= 6.7.37 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Read CVSS 6.5 · 08.10.202506.05.20268.8Slider Revolution 7.0.0 - 7.0.10 - Authenticated (Subscriber+) Arbitrary File Upload via _get_media_url CVSS 8.8 · 06.05.202619.05.20265.3Slider Revolution <= 7.0.9 - Unauthenticated Sensitive Information Exposure via 'sliders/stream' CVSS 5.3 · 19.05.202601.06.20264.3Slider Revolution 7.0.0 - 7.0.14 - Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure CVSS 4.3 · 01.06.20264.3Slider Revolution 6.0.0-6.7.55 and 7.0.0-7.0.14 - Missing Authorization to Authenticated (Contributor+) Arbitrary Plugin Deactivation CVSS 4.3 · 01.06.202608.06.20266.5Slider Revolution 7.0 - 7.0.10 - Authenticated (Subscriber+) Sensitive Information Disclosure CVSS 6.5 · 08.06.202630.06.20267.2Slider Revolution 7.0.0-7.0.16 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 30.06.2026

Strategic Overview

Avg CVSSMedium
6.6/ 10
Patch Coverage100%
Open

0

Fixed

23

Get automatic notifications for all Slider Revolution vulnerabilities before they are exploited.

Vulnerability Records

23 records
2026-06-30 00:00CVE-2026-57678
7.2
High
darooYes
2026-06-08 19:07CVE-2026-7542
6.5
Medium
Luc Huynh from Noventiq RedTeamYes
2026-06-01 10:46CVE-2026-9050
4.3
Medium
Nguyen Ngoc Duc (duc193)Yes
2026-06-01 10:41CVE-2026-9048
4.3
Medium
Prickly CactusYes
2026-05-19 20:43CVE-2026-6728
5.3
Medium
Nos1x0Yes
2026-05-06 16:15CVE-2026-6692
8.8
High
h0xiloYes
2025-10-08 00:00CVE-2025-10249
6.5
Medium
stealthcopterYes
2025-08-28 00:00CVE-2025-9217
6.5
Medium
stealthcopterYes
2024-09-30 18:27CVE-2024-8107
6.4
Medium
wesley (wcraft)Yes
2024-06-28 00:00CVE-2024-37449
4.4
Medium
wesley (wcraft)Yes
Showing 1–10 of 23 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C