CVE-2026-6692Disclosure

MEDIUMCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0.0 to 7.0.10 via the '_get_media_url' and '_check_file_path' function. This is due to insufficient file type validation. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible. The vulnerability was partially patched in version 7.0.10 and fully patched in version 7.0.11.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 10 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 3 classified signals
  • Peaked 6d ago at 4 mentions (2026-05-07); latest day: 1
  • 10 total mentions across 7 days

Deep dive

Activity timeline10 mentions / 7d
01234Mentions · 2026-05-07: 4Mentions · 2026-05-14: 1Mentions · 2026-05-15: 1Mentions · 2026-05-19: 1Mentions · 2026-05-25: 1Mentions · 2026-05-27: 1Mentions · 2026-05-30: 1Active Exploitation · 2026-05-15: 1Patch / Workaround · 2026-05-07: 2Patch / Workaround · 2026-05-14: 1Technical Details · 2026-05-07: 205-0705-1405-1505-1905-2505-2705-30
Signal classification4 categories
Disclosure
330.0%
Patch
330.0%
General
330.0%
Active Exploitation
110.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-05-074
Disclosure2Patch2
2026-05-141
Patch1
2026-05-151
Active Exploitation1
2026-05-191
General1
2026-05-251
Disclosure1
2026-05-271
General1
2026-05-301
General1
Full discourse10 posts
  • IT-Connect.fr@ITConnect_fr
    Patch

    ⚠️ WordPress : le plugin Slider Revolution doit être mis à jour (CVE-2026-6692) Plus d'infos par ici : - https://www.it-connect.fr/wordpress-le-plugin-slider-revolution-doit-etre-mis-a-jour-cve-2026-6692/ #wordpress #infosec #web https://t.co/WnstgOBySR

    Post summary

    The tweet alerts users that the Slider Revolution plugin must be patched for CVE‑2026‑6692, but offers no proof‑of‑concept, exploit code, or details of active exploitation.

    03021556
    11.5K followersView on X
  • Threat Intelligence@threatintel
    Patch

    #ThreatProtection #CVE-2026-6692 - Slider Revolution Plugin #vulnerability, read more about Symantec's protection: https://www.broadcom.com/support/security-center/protection-bulletin/cve-2026-6692-slider-revolution-plugin-vulnerability

    Post summary

    Broadcom Symantec issued a protection bulletin for CVE-2026-6692, offering mitigation guidance for the Slider Revolution Plugin vulnerability, without presenting PoC details or evidence of active exploitation.

    010211.3K
    115.1K followersView on X
  • Dr. Siraj Dokadia@SirajD_Official
    Disclosure

    CVE-2026-6692 - Slider Revolution Plugin vulnerability https://dy.si/1qd1m https://t.co/5QdUON6GRw

    Post summary

    The tweet announces the discovery of a new CVE (CVE-2026-6692) affecting the Slider Revolution plugin and provides links for further details.

    0001042
    17 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    【脆弱性情報】 CVE-2026-6692 Slider Revolutionの脆弱性について https://www.cybernote.click/2026/05/21/%e3%80%90%e8%84%86%e5%bc%b1%e6%80%a7%e6%83%85%e5%a0%b1%e3%80%91-cve-2026-6692-slider-revolution%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6/ #IT #Security #cybersecurity

    Post summary

    The post only announces the existence of CVE-2026-6692 for Slider Revolution and provides a link to a Japanese article with unspecified details, lacking concrete information on PoC, exploit, patches, or ongoing attacks.

    0000036
    209 followersView on X
  • Shawn Bertin@shbertin
    General

    CVE-2026-6692 - Slider Revolution Plugin vulnerability https://dy.si/9T8Ta https://t.co/4GxDKV3iF4

    Post summary

    The tweet references CVE‑2026‑6692 as a vulnerability in the Slider Revolution plugin but offers no further technical or exploit details.

    0000099
    200 followersView on X
  • Guru@Guru0791
    General

    CVE-2026-6692 - Slider Revolution Plugin vulnerability https://dy.si/o8YGem2 https://t.co/FV187z0pcU

    Post summary

    The tweet merely names CVE-2026-6692 for Slider Revolution Plugin and includes a link, offering no substantive details or actionable information.

    0000048
    6 followersView on X
  • Nicolas Coolman@NicolasCoolman
    Active Exploitation

    🚨 WordPress : Exploitation Active de la vulnérabilité CVE-2026-6692 dans Le Plugin Slider Revolution. #zoneantimalware https://t.co/VPvnUuDb6m

    Post summary

    The tweet reports that CVE-2026-6692 in the Slider Revolution WordPress plugin is currently being actively exploited in the wild.

    0000076
    87 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6692 The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0.0 to 7.0.10 via the '_get_media_url' and '_check_file_path' function. … https://www.cve.org/CVERecord?id=CVE-2026-6692

    Post summary

    The text provides a concise disclosure of CVE‑2026‑6692, highlighting an arbitrary file upload issue in Slider Revolution 7.0.0–7.0.10, without any mention of PoC, exploit tools, active exploitation, or patches.

    0000098
    57.4K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-6692 The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0.0 to 7.0.10 via the '… CVSS 8.8 Full analysis → https://sec.kaitan.id/cves/CVE-2026-6692 #WordPress #CyberSecurity #InfoSec

    Post summary

    The text discloses a new high‑severity vulnerability (CVSS 8.8) in Slider Revolution for WordPress, detailing an arbitrary file upload flaw affecting versions 7.0.0‑7.0.10.

    0000045
    518 followersView on X
  • thibault@akril
    Patch

    [IT-Connect] - WordPress : le plugin Slider Revolution doit être mis à jour (CVE-2026-6692) - https://www.it-connect.fr/wordpress-le-plugin-slider-revolution-doit-etre-mis-a-jour-cve-2026-6692/ 👌😁

    Post summary

    The message warns that the Slider Revolution plugin for WordPress must be updated to address CVE-2026-6692.

    0000053
    691 followersView on X

Explore more