The Slider Hero plugin for WordPress (used to create slideshows) could be exploited by unauthenticated attackers in versions 8.2.0 and earlier. This exploit is possible because of missing or incorrect security measures on the plugin’s qc_slider_hero_duplicate() function. This allows attackers to duplicate slides if they can convince a site administrator to click on a link.