---
id: CVE-2026-86786
title: >-
  The Slider Pro WordPress plugin through 1.0.0 does not perform any capability
  or authorisation check on one of its AJAX actions, allowing unauthenticated
  users to retrieve the title, excerpt and permalink of non-public posts,
  including d…
summary: >-
  The Slider Pro WordPress plugin through 1.0.0 does not perform any capability
  or authorisation check on one of its AJAX actions, allowing unauthenticated
  users to retrieve the title, excerpt and permalink of non-public posts,
  including d…
severity: none
cwe:
  - CWE-200
product: Slider Pro
affected:
  - slider_pro <= 1.0.0
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T07:16:59.620'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86786'
references:
  - url: 'https://wpscan.com/vulnerability/0645bcad-740e-452e-9d73-3e47ddd83f8b/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T06:48:36.102Z'
---

## Overview

The Slider Pro WordPress plugin through 1.0.0 does not perform any capability or authorisation check on one of its AJAX actions, allowing unauthenticated users to retrieve the title, excerpt and permalink of non-public posts, including drafts, pending, scheduled, private and trashed posts, as well as post revisions and media metadata.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
