CVE-2026-86786
Received Received - Intake

Unauthenticated Post Data Exposure in Slider Pro WordPress Plugin

Vulnerability report for CVE-2026-86786, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: WPScan

Description

The Slider Pro WordPress plugin through 1.0.0 does not perform any capability or authorisation check on one of its AJAX actions, allowing unauthenticated users to retrieve the title, excerpt and permalink of non-public posts, including drafts, pending, scheduled, private and trashed posts, as well as post revisions and media metadata.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Slider Pro 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Slider Pro WordPress plugin allows unauthenticated users to access sensitive information from non-public posts. The issue occurs because the plugin does not check user permissions before processing an AJAX action, letting attackers retrieve titles, excerpts, and permalinks of drafts, private posts, scheduled content, and other restricted data.

Detection Guidance

Check for unauthorized access to non-public posts by reviewing server logs for unusual AJAX requests to the Slider Pro plugin endpoints. Look for requests to /wp-admin/admin-ajax.php with parameters indicating data retrieval of drafts or private content.

Impact Analysis

If you use the Slider Pro plugin version 1.0.0 or below, attackers could steal sensitive information from your WordPress site without needing access credentials. This includes unpublished content, private posts, and media details, potentially exposing confidential or proprietary data.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA if it results in unauthorized access to personal or sensitive data. Organizations may face legal penalties, reputational damage, and loss of trust due to data exposure from non-public posts.

Mitigation Strategies

Disable the Slider Pro WordPress plugin immediately if installed. Monitor network traffic for suspicious activity related to post data access. Consider implementing a web application firewall to block unauthorized AJAX requests to the vulnerable endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86786. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart