Revolution Slider <= 6.6.12 - Author+ Remote Code Execution
25Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Attendepss 2.5%
from disclosure to weapon
Published on NVDJun 19
VulnCheck+639d
exploitation probability
2.5%top 17% of all CVEs
observed exploitation
yesVulnCheck
The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Execution in some server configurations.
Affected products
Unknown · Slider Revolution