CVE-2026-86786None▾ SunlitThe Slider Pro WordPress plugin through 1.0.0 does not perform any capability or authorisation check on one of its AJAX actions, allowing unauthenticated users to retrieve the title, excerpt and permalink of non-public posts, including d…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The Slider Pro WordPress plugin through 1.0.0 does not perform any capability or authorisation check on one of its AJAX actions, allowing unauthenticated users to retrieve the title, excerpt and permalink of non-public posts, including drafts, pending, scheduled, private and trashed posts, as well as post revisions and media metadata.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2022-31746Medium· 6.5Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header
CVE-2026-105707Medium· 5.3A security vulnerability has been detected in uptrace up to 2.1.0-beta.8
CVE-2026-105752Low· 3.1vLLM is an inference and serving engine for large language models
CVE-2026-105748Medium· 4.3Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem
CVE-2026-105684Medium· 4.3Penpot is an open-source design and prototyping platform
CVE-2026-105635High· 7.4Plane is an open-source project management tool