CVE-2026-66635: WordPress Slider by 10Web plugin <= 1.2.62 - CSRF to Arbitrary File Deletion vulnerability
Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Slider by 10Webto a version that resolves this vulnerability.Fixed in 1.2.62
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
An attacker does not need an account, but exploitation requires a victim to interact with a malicious request while authenticated to a vulnerable WordPress site. The attack is network-reachable and has low complexity.
Which installations are affected?
Slider by 10Web versions 1.2.62 and earlier are identified as affected. The available data does not state whether any particular plugin or WordPress configuration changes exposure.
What is the likely impact if exploitation succeeds?
Successful exploitation can result in arbitrary file deletion, causing a high availability impact. The provided data does not identify confidentiality or integrity impact.