VYPR
Critical severity9.1NVD Advisory· Published Jun 15, 2026· Updated Jun 15, 2026

CVE-2026-39465

CVE-2026-39465

Description

A remote code execution vulnerability in MetaSlider plugin <=3.106.0 allows authenticated editors to execute arbitrary commands, leading to full site compromise.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A remote code execution vulnerability in MetaSlider plugin <=3.106.0 allows authenticated editors to execute arbitrary commands, leading to full site compromise.

Vulnerability

The Responsive Slider by MetaSlider plugin for WordPress versions up to and including 3.106.0 contains a remote code execution (RCE) vulnerability. The flaw resides in the editor functionality, allowing users with editor-level access to inject and execute arbitrary PHP code. The vulnerability is present in the plugin's slider management interface, where insufficient input validation and sanitization occur. [1]

Exploitation

An attacker must have a WordPress account with editor privileges or higher. The attacker can craft a malicious request to the plugin's editor endpoint, injecting PHP code that gets executed on the server. No additional user interaction is required beyond the attacker's own actions. The vulnerability is expected to be exploited in mass campaigns targeting thousands of sites. [1]

Impact

Successful exploitation allows the attacker to execute arbitrary commands on the target server, potentially gaining backdoor access and full control over the WordPress site. This can lead to data theft, site defacement, malware distribution, and further compromise of the hosting environment. [1]

Mitigation

The vulnerability is fixed in version 3.107.0 of the plugin. Users are strongly advised to update immediately. For those unable to update, Patchstack provides a virtual mitigation rule that blocks attacks until the update is applied. The vulnerability is listed as highly dangerous and expected to be exploited. [1]

AI Insight generated on Jun 15, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.