Web Hack List

Collected research

RevSlider

Slider Revolution Plugin Critical Vulnerability Being Exploited

The Slider Revolution WordPress plugin exposed an admin-ajax action that returned whatever file path it was handed, so an unauthenticated attacker could download wp-config.php and take the database credentials. It was patched silently, then attacked at scale because the plugin ships bundled inside many commercial themes.

Record

Document
Slider Revolution Plugin Critical Vulnerability Being Exploited
Researcher
@sucurisecurity
Published by
Sucuri Blog
Date
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of @sucurisecurity, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .