CVE-2026-9050 – Slider Revolution 6.0.0-6.7.55 and 7.0.0-7.0.14 – Missing Authorization to Authenticated (Contributor+) Arbitrary Plugin Deactivation
CVE ID :CVE-2026-9050
Published : June 2, 2026, 12:16 a.m. | 15 minutes ago
Description :The Slider Revolution plugin for WordPress in versions 6.0.0-6.7.55 and 7.0.0-7.0.14 is vulnerable to unauthorized modification of data. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Contributor-level access and above, to deactivate any active plugin installed on the site.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more…