Executive brief
Slider Revolution, a popular WordPress plugin used for creating visual content and sliders, contains a security flaw that allows for reflected cross-site scripting. An attacker could trick a site administrator or visitor into clicking a malicious link, allowing the attacker to run unauthorized scripts in their browser. This could lead to the theft of session cookies, unauthorized actions performed on behalf of the user, or redirection to malicious websites.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the ThemePunch Slider Revolution plugin for WordPress (versions 7.0.0-7.0.16). The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by inducing a user to interact with a specially crafted URL. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized administrative actions. The issue is resolved in version 7.1.0.
Affected products
- ThemePunch Slider Revolution 7.0.0 through 7.0.16
Timeline
- 2026-06-15: disclosed: Reported by researcher daroo
- 2026-06-30: advisory: Patchstack advisory published
- 2026-07-02: advisory: NVD published CVE-2026-57678
- 2026-07-02: patched: Version 7.1.0 identified as patched version