Nxploited[verified]@NxploitedPoC
The post announces a PoC for CVE‑2026‑1405, highlighting an unauthenticated arbitrary file upload vulnerability in Slider Future <= 1.0.5, with a GitHub link but no discussion of active exploitation or available patches.
Quttera - eCommerce Security[verified]@MNovofastovskyDisclosure
The post announces a critical file upload vulnerability in the Slider Future WordPress plugin (CVE‑2026‑1405) with a CVSS score of 9.8, noting that attackers can upload PHP shells without authentication, and urges users to update or remove the plugin and audit uploads.
Quttera - eCommerce Security[verified]@MNovofastovskyDisclosure
CVE-2026-1405 is a critical, unauthenticated arbitrary file upload vulnerability in the Slider Future WordPress plugin (≤1.0.5) with a CVSS score of 9.8; users are advised to update or remove the plugin and audit server directories for malicious uploads.
CVETodo[verified]@CveTodoDisclosure
A critical flaw in the Slider Future WordPress plugin permits unauthenticated file uploads, potentially enabling remote code execution, but no PoC, exploit code, patch or active exploitation is reported.
ZAST AI[verified]@zast_aiPatch
The message recommends specific WordPress code changes and function usage to mitigate CVE‑2026‑1405, offering a workaround but lacking exploit details.
Geng Yang[verified]@geng_zastPatch
CVE-2026-1405 is a WordPress plugin vulnerability affecting all versions up to 1.0.5; users should deactivate the plugin or apply the permission_callback and extension filter patches to mitigate an open‑door RCE risk.
pdnuclei-bot@pdnuclei_botDisclosure
The post announces the discovery of an unauthenticated arbitrary file upload flaw in WordPress Slider Future <= 1.0.5, providing technical details and a link for further information but no evidence of exploitation or remediation steps.
0day Signal@0dayPublishingDisclosure
The post announces CVE‑2026‑1405, noting that an unauthenticated file upload in Slider Future 1.0.5 or earlier skips MIME validation, enabling trivial remote code execution.