Executive brief
A vulnerability in the Soliloquy image slider plugin for WordPress allows users with basic account access to view private information. This includes draft slider content, unpublished image links, and internal configuration settings created by site administrators. This could lead to the exposure of sensitive media or marketing materials before they are intended for public release.
Technical details
The Slider by Soliloquy plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 2.8.1. The flaw exists within the map_meta_cap function, which fails to properly restrict access to slider metadata. An authenticated attacker with subscriber-level permissions or higher can exploit this to retrieve draft slider configurations, unpublished media URLs, and captions authored by higher-privileged users like administrators or editors. This is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). A patch has been released in the plugin's trunk/latest versions.
Affected products
- Soliloquy Slider by Soliloquy – Responsive Image Slider for WordPress Up to, and including, 2.8.1
Timeline
- 2026-05-22: disclosed: CVE published by Wordfence/NVD
References
- https://plugins.trac.wordpress.org/browser/soliloquy-lite/tags/2.8.1/includes/global/posttype.php
- https://plugins.trac.wordpress.org/browser/soliloquy-lite/tags/2.8.1/includes/global/posttype.php
- https://plugins.trac.wordpress.org/browser/soliloquy-lite/tags/2.8.1/includes/global/posttype.php
- https://plugins.trac.wordpress.org/browser/soliloquy-lite/trunk/includes/global/posttype.php
- https://plugins.trac.wordpress.org/browser/soliloquy-lite/trunk/includes/global/posttype.php
- https://plugins.trac.wordpress.org/browser/soliloquy-lite/trunk/includes/global/posttype.php
- https://plugins.trac.wordpress.org/changeset/3538404/soliloquy-lite/trunk/includes/global/posttype.php?old=3395148&old_path=soliloquy-lite%2Ftrunk%2Fincludes%2Fglobal%2Fposttype.php