CVE-2026-1405Disclosure

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'slider_future_handle_image_upload' function in all versions up to, and including, 1.0.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • Peaked 4d ago at 2 mentions (2026-02-19); latest day: 1
  • 8 total mentions across 7 days

Deep dive

Activity timeline8 mentions / 7d
01122Mentions · 2026-02-17: 1Mentions · 2026-02-18: 1Mentions · 2026-02-19: 2Mentions · 2026-02-20: 1Mentions · 2026-03-08: 1Mentions · 2026-03-09: 1Mentions · 2026-03-24: 1PoC Mentioned / Linked · 2026-02-20: 1PoC Mentioned / Linked · 2026-03-24: 1Exploit Tool / Code · 2026-02-20: 1Patch / Workaround · 2026-02-17: 1Patch / Workaround · 2026-02-18: 1Patch / Workaround · 2026-03-08: 1Patch / Workaround · 2026-03-09: 1Technical Details · 2026-02-18: 1Technical Details · 2026-02-19: 2Technical Details · 2026-02-20: 1Technical Details · 2026-03-08: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-24: 102-1702-1802-1902-2003-0803-0903-24
Signal classification3 categories
Disclosure
562.5%
Patch
225.0%
PoC
112.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-171
Patch1
2026-02-181
Patch1
2026-02-192
Disclosure2
2026-02-201
PoC1
2026-03-081
Disclosure1
2026-03-091
Disclosure1
2026-03-241
Disclosure1
Full discourse8 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-1405 - critical 🚨 WordPress Slider Future <= 1.0.5 - Unauthenticated Arbitrary File Upload > Slider Future WordPress plugin <= 1.0.5 contains an unrestricted file upload vulnerab... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-1405 @pdnuclei #NucleiTempl...

    Post summary

    The post announces the discovery of an unauthenticated arbitrary file upload flaw in WordPress Slider Future <= 1.0.5, providing technical details and a link for further information but no evidence of exploitation or remediation steps.

    00021125
    902 followersView on X
  • Nxploited@Nxploited
    PoC

    Slider Future &lt;= 1.0.5 - Unauthenticated Arbitrary File Upload PoC: https://github.com/Nxploited/CVE-2026-1405/ #cybersecurity #Hacking #wordpress

    Post summary

    The post announces a PoC for CVE‑2026‑1405, highlighting an unauthenticated arbitrary file upload vulnerability in Slider Future <= 1.0.5, with a GitHub link but no discussion of active exploitation or available patches.

    0001163
    84 followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Disclosure

    CVE-2026-1405 Critical #WordPress plugin vulnerability https://nvd.nist.gov/vuln/detail/CVE-2026-1405 The Slider Future plugin ≤ 1.0.5 contains an unauthenticated arbitrary file upload flaw due to missing file-type validation. Attackers can upload malicious files (like PHP shells) directly to the server — potentially leading to remote code execution and full site compromise. 🛠 Why it matters: No login required and a CVSS score of 9.8 (critical), making exploitation possible remotely with minimal effort. 🔧 Mitigation: Update the plugin immediately or remove it if unused, then audit uploads and server files for unauthorized payloads. #WordPressSecurity #CVE #WebSecurity #CyberThreats #FullPerimeterProtection #SilentRisk

    Post summary

    The post announces a critical file upload vulnerability in the Slider Future WordPress plugin (CVE‑2026‑1405) with a CVSS score of 9.8, noting that attackers can upload PHP shells without authentication, and urges users to update or remove the plugin and audit uploads.

    0001066
    37 followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Disclosure

    CVE-2026-1405 Critical #WordPress plugin vulnerability https://nvd.nist.gov/vuln/detail/CVE-2026-1405 The Slider Future plugin (≤ 1.0.5) contains an unauthenticated arbitrary file upload flaw caused by missing file-type validation in the slider_future_handle_image_upload function. Attackers can upload malicious files (e.g., PHP shells) and potentially execute code on the server. ⚠️ Why it matters: The bug has a CVSS score of 9.8 (critical) and requires no authentication, allowing remote attackers to compromise confidentiality, integrity, and availability of affected WordPress sites. 🛠 Mitigation: Update or remove the vulnerable plugin immediately and review uploaded files and server directories for suspicious payloads. #WordPressSecurity #CVE #WebSecurity #CyberThreats #FullPerimeterProtection #SilentRisk

    Post summary

    CVE-2026-1405 is a critical, unauthenticated arbitrary file upload vulnerability in the Slider Future WordPress plugin (≤1.0.5) with a CVSS score of 9.8; users are advised to update or remove the plugin and audit server directories for malicious uploads.

    0000066
    37 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-1405** pertains to a critical security flaw in the **Slider Future** plugin for WordPress, specifically in versions up to and including **1.0.5**. The vulnerability arises from **missing file type validation** during the file upload process within the `slider_future_handle_image_upload` function. This flaw allows **unauthenticated attackers** to upload **arbitrary files** to the server, potentially leading to **remote code execution (RCE)**. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution https://cvetodo.com/cve/CVE-2026-1405

    Post summary

    A critical flaw in the Slider Future WordPress plugin permits unauthenticated file uploads, potentially enabling remote code execution, but no PoC, exploit code, patch or active exploitation is reported.

    0000036
    20 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-1405: Slider Future &lt;= 1.0.5 - Unauthen... Completely unauthenticated file upload in Slider Future skips MIME validation, offering trivial RCE via the slider_futur... https://zerodaysignal.com/vulnerability/CVE-2026-1405 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑1405, noting that an unauthenticated file upload in Slider Future 1.0.5 or earlier skips MIME validation, enabling trivial remote code execution.

    0000058
    131 followersView on X
  • ZAST AI@zast_ai
    Patch

    Immediate Action Required: Update permission_callback to check for upload_files capabilities. Implement strict extension and MIME-type allow-lists. Switch to media_handle_sideload() for secure processing. Check detail here:https://www.cve.org/CVERecord?id=CVE-2026-1405 @WordPress @wordfence #AppSec #ZAST #VulnerabilityResearch #WordPress #RCE

    Post summary

    The message recommends specific WordPress code changes and function usage to mitigate CVE‑2026‑1405, offering a workaround but lacking exploit details.

    0000066
    31 followersView on X
  • Geng Yang@geng_zast
    Patch

    CVE-2026-1405 affects all versions up to 1.0.5. If you have this plugin active, your server is currently an open door. Deactivate immediately or apply the permission_callback and extension filter patches! Check detail here:https://www.cve.org/CVERecord?id=CVE-2026-1405 @wordpress @wordfence #AppSec #ZAST #VulnerabilityResearch #WordPress #RCE

    Post summary

    CVE-2026-1405 is a WordPress plugin vulnerability affecting all versions up to 1.0.5; users should deactivate the plugin or apply the permission_callback and extension filter patches to mitigate an open‑door RCE risk.

    0000048
    42 followersView on X

Explore more