CVE-2026-39465: WordPress Responsive Slider by MetaSlider plugin <= 3.106.0 - Remote Code Execution (RCE) vulnerability
Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider <= 3.106.0 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Responsive Slider by MetaSlider pluginto a version that resolves this vulnerability.Fixed in 3.107.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39465?
CVE-2026-39465 has a severity rating of 9.1, classified as critical.
What impact does CVE-2026-39465 have on the MetaSlider plugin?
CVE-2026-39465 allows for remote code execution, enabling unauthorized users to execute malicious code.
How do I fix CVE-2026-39465?
To fix CVE-2026-39465, update the MetaSlider Responsive Slider plugin to version 3.107.0 or later.
Which versions of MetaSlider are affected by CVE-2026-39465?
CVE-2026-39465 affects all versions of the MetaSlider Responsive Slider plugin up to and including 3.106.0.
Who is at risk due to CVE-2026-39465?
Users of the MetaSlider plugin who have not updated to a patched version are at risk due to the RCE vulnerability.