Junglewise Threat Intelligence

CVE-2026-9050: ThemePunch Slider Revolution unauthorized plugin deactivation

CVE-2026-9050 · Severity: medium · CVSS 4.3 · Published 2026-06-02

Technologies: ThemePunch Slider Revolution. Vendors: ThemePunch.

Executive brief

Slider Revolution is a popular WordPress plugin used to create interactive sliders and visual content. A security flaw allows users with low-level 'Contributor' accounts to deactivate any other plugin installed on the website. This could lead to service disruptions, the disabling of security tools, or the loss of critical site functionality.

Technical details

The Slider Revolution plugin for WordPress (versions 6.0.0-6.7.55 and 7.0.0-7.0.14) contains a missing authorization vulnerability (CWE-862). The plugin fails to properly verify user permissions before executing certain actions. An authenticated attacker with at least Contributor-level privileges can exploit this flaw to deactivate any active plugin on the WordPress installation. This is achieved via a network request to an affected endpoint that lacks sufficient capability checks. While the vulnerability does not directly allow for data exfiltration or remote code execution, it can be used to disable security plugins or disrupt site operations.

Affected products

  • ThemePunch Slider Revolution 6.0.0 - 6.7.55, 7.0.0 - 7.0.14

Timeline

  • 2026-06-01: disclosed: Vulnerability reported by Wordfence
  • 2026-06-02: advisory: NVD publication date

References

Related threats