CVE-2023-2359: Themepunch Slider Revolution
High severity, CVSS 8.8. EPSS: 2.5% chance of exploitation in the next 30 days.
The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Execution in some server configurations.
Affected products
- Themepunch Slider Revolution: up to and including 6.6.12
Published 2023-06-19. Last modified 2026-06-17.