The ThemePunch Slider Revolution (revslider) plugin prior to 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and previous versions for Wordpress does not properly restrict access to administrator AJAX functionality, which allows remote malicious users to (1) upload and execute arbitrary files via an update_plugin action; (2) delete arbitrary sliders via a delete_slider action; and (3) create, (4) update, (5) import, or (6) export arbitrary sliders via unspecified vectors.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
themepunch showbiz pro |
||
themepunch slider revolution |