Vulnerability Report: Critical File Upload Flaw in Slider Revolution Plugin
On April 18, 2026, a significant security vulnerability was discovered in the Slider Revolution plugin for WordPress, affecting versions 7.0.0 to 7.0.10. This flaw allows authenticated users with subscriber-level access and above to upload malicious files, potentially leading to remote code execution.
The vulnerability arises from inadequate file type validation, enabling attackers to exploit the plugin’s functionality. With over 5 million installations, approximately 45,000 sites are at risk.
The ThemePunch development team promptly responded, releasing a patch on May 4, 2026. Users are urged to update to version 7.0.11 immediately.
The risk level of this vulnerability is rated as high (CVSS 8.8). For enhanced security, Wordfence users with premium services received a firewall rule on April 20, with free users to follow on May 20. Stay safe by ensuring your plugin is updated!
Source: View Original Report
