Unrated severityNVD Advisory· Published Oct 6, 2026
CVE-2026-86786
CVE-2026-86786
Description
The Slider Pro WordPress plugin through 1.0.0 does not perform any capability or authorisation check on one of its AJAX actions, allowing unauthenticated users to retrieve the title, excerpt and permalink of non-public posts, including drafts, pending, scheduled, private and trashed posts, as well as post revisions and media metadata.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<=1.0.0+ 1 more
- (no CPE)range: <=1.0.0
- (no CPE)range: <=1.0.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.