CVE-2026-86786: Unknown Slider Pro

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The Slider Pro WordPress plugin through 1.0.0 does not perform any capability or authorisation check on one of its AJAX actions, allowing unauthenticated users to retrieve the title, excerpt and permalink of non-public posts, including drafts, pending, scheduled, private and trashed posts, as well as post revisions and media metadata.

Affected products

  • Unknown Slider Pro: up to and including 1.0.0

Published 2026-10-06. Last modified 2026-10-06.