Input validation vulnerability in Slider Revolution 6.6.12

The Slider Revolution plugin for WordPress is vulnerable to security risks due to a missing file type validation in versions up to 6.6.12. This means that anyone with administrator-level access can upload files to the affected site’s server, potentially allowing them to execute code remotely. By default, only administrators can exploit this vulnerability, but the privilege can be granted to users with lower privileges, such as authors.

Detected in:

Slider Revolution fixed vulnerable versions: >= * <= 6.6.12

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.