VYPR
Medium severity4.3NVD Advisory· Published Jun 2, 2026

CVE-2026-9048

CVE-2026-9048

Description

Slider Revolution plugin for WordPress versions 7.0.0-7.0.14 expose sensitive social media API credentials via an AJAX action.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Slider Revolution plugin for WordPress versions 7.0.0-7.0.14 expose sensitive social media API credentials via an AJAX action.

Vulnerability

The Slider Revolution plugin for WordPress, specifically versions 7.0.0 through 7.0.14, contains a vulnerability in the slider.get.full AJAX Action. This vulnerability allows for the exposure of sensitive data stored within the plugin's settings.

Exploitation

An attacker with at least Contributor-level access to a WordPress site can exploit this vulnerability. By triggering the slider.get.full AJAX action, the attacker can extract sensitive information, including raw social media API credentials such as the Instagram OAuth token, Flickr API key, YouTube Data API key, and Facebook App ID, which are configured in any slider's settings.

Impact

Successful exploitation of this vulnerability allows an authenticated attacker to gain access to sensitive social media API credentials. This could lead to unauthorized access to associated social media accounts, potential misuse of API functionalities, and further compromise of user data or services connected to these credentials.

Mitigation

This vulnerability affects Slider Revolution versions 7.0.0 through 7.0.14. Users are advised to update to a patched version as soon as it becomes available. Specific patch details and release dates are not yet disclosed in the available references. The vendor website [1] provides general information about the plugin but does not contain specific mitigation details for this vulnerability.

AI Insight generated on Jun 2, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.