Junglewise Threat Intelligence

CVE-2026-6728: ThemePunch Slider Revolution sensitive information exposure in get_stream_data

CVE-2026-6728 · Severity: medium · CVSS 5.3 · Published 2026-05-20

Technologies: ThemePunch Slider Revolution. Vendors: ThemePunch.

Executive brief

Slider Revolution is a popular WordPress plugin used to create interactive visual content and slideshows. A security flaw allows unauthorized individuals to bypass privacy settings and view content that was intended to be password-protected, such as private posts or product details. This could lead to the exposure of sensitive business information or restricted customer content.

Technical details

The Slider Revolution plugin for WordPress contains an information exposure vulnerability within the 'get_stream_data()' function. Due to insufficient access control checks when retrieving data streams, an unauthenticated remote attacker can invoke this function to bypass password protections on posts, pages, and WooCommerce products. By exploiting this flaw, an attacker can read the full content of restricted posts that would otherwise require a password to view. The vulnerability is present in all versions up to 7.0.9; users should update to the latest available version to mitigate the risk.

Affected products

  • ThemePunch Slider Revolution up to, and including, 7.0.9

Timeline

  • 2026-05-20: advisory: Initial disclosure of CVE-2026-6728

References

Related threats