Junglewise Threat Intelligence

CVE-2026-14244: Jssor Slider WordPress plugin directory traversal in url parameter

CVE-2026-14244 · Severity: high · CVSS 7.5 · Published 2026-07-08

Executive brief

The Jssor Slider plugin for WordPress, which is used to create image slideshows, contains a security flaw that allows unauthorized individuals to access files on the website's server. By exploiting this vulnerability, an attacker could read sensitive configuration files or system data, potentially leading to a full compromise of the website or its database. This issue affects all versions of the plugin up to and including 3.1.24.

Technical details

A directory traversal vulnerability exists in the Jssor Slider plugin for WordPress due to insufficient validation of the 'url' parameter in several administrative and dispatcher components. Specifically, the flaw is located in class-jssor-slider-admin-controller.php and jssor-slider-dispatcher.php. An unauthenticated remote attacker can exploit this by sending specially crafted requests containing path traversal sequences (e.g., ../../) to access files outside of the intended directory. This allows for the unauthorized reading of sensitive local files, such as wp-config.php, which may contain database credentials. The vulnerability is present in all versions up to and including 3.1.24.

Affected products

  • jssor.com Jssor Slider by jssor.com up to, and including, 3.1.24

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: advisory

References