CVE-2026-86786: Slider Pro <= 1.0.0 - Unauthenticated Sensitive Data Disclosure via sliderpro_multiple_images
The Slider Pro WordPress plugin through 1.0.0 does not perform any capability or authorisation check on one of its AJAX actions, allowing unauthenticated users to retrieve the title, excerpt and permalink of non-public posts, including drafts, pending, scheduled, private and trashed posts, as well as post revisions and media metadata.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any unauthenticated remote user can invoke the affected AJAX action because it lacks capability and authorization checks. No WordPress account or elevated role is required.
What information can be exposed?
The affected action can disclose the title, excerpt, and permalink of non-public posts. This includes drafts, pending, scheduled, private, and trashed posts, as well as post revisions and media metadata.
How can I determine whether my site is affected?
Sites using the Slider Pro WordPress plugin through version 1.0.0 are affected. The issue is specifically associated with the sliderpro_multiple_images AJAX action.