Executive brief
A vulnerability in the Responsive Slider by MetaSlider plugin for WordPress allows users with high-level permissions to execute unauthorized code on the server. This plugin is used to create image and video slideshows on websites. If exploited, an attacker could take complete control of the website, access sensitive data, or install backdoors for persistent access.
Technical details
The Responsive Slider by MetaSlider plugin for WordPress is vulnerable to Remote Code Execution (RCE) due to improper control of generation of code (CWE-94). The vulnerability exists in versions up to and including 3.106.0. An attacker with 'Editor' or higher privileges can exploit this flaw to inject and execute arbitrary PHP code on the server. This is a network-based attack that does not require user interaction but does require high-level authentication. The issue has been addressed in version 3.107.0.
Affected products
- MetaSlider Responsive Slider by MetaSlider <= 3.106.0
Timeline
- 2026-02-21: other: Vulnerability reported by researcher Marc-André Beaulieu
- 2026-04-20: advisory: Patchstack advisory published
- 2026-06-15: disclosed: CVE published to NVD
- 2026-04-20: patched: Fixed in version 3.107.0