Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemePunch Slider Revolution allows Reflected XSS.

This issue affects Slider Revolution: from 7.0.0 through 7.0.16.
Published: 2026-07-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper Neutralization of Input During Web Page Generation ('Cross‑Site Scripting') vulnerability in ThemePunch Slider Revolution allows Reflected XSS, enabling an attacker to inject malicious scripts that execute in the browsers of site visitors when the affected plugin renders unsanitized input.

Affected Systems

The affected product is the WordPress Slider Revolution plugin from ThemePunch, covering all releases from 7.0.0 through 7.0.16. Any WordPress site that has installed one of these plugin versions user submits or accesses crafted input that the Slider Revolution plugin renders without proper escaping, a malicious script can be executed in the browser context of visitors.

Risk and Exploitability

The CVSS score of 7.1 class The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is inferred that a reflected XSS can be triggered by an attacker sending a crafted request containing malicious input—typically via a URL parameter or an untrusted form field—without requiring authentication or special privileges. The impact is limited to browsers of site visitors, but could be amplified if thesite cookies.

Generated by OpenCVE AI on July 21, 2026 at 11:24 UTC.

Remediation

Vendor Solution

Update the WordPress Slider Revolution Plugin to the latest available version (at least 7.1.0).


OpenCVE Recommended Actions

  • Update the WordPress Slider Revolution plugin to the latest available version (at least 7.1.0).
  • If you cannot uninstall the plugin to eliminate the XSS vector associated with, configure a Web Application Firewall to block reflected XSS and set Content Security Policy headers that restrict script execution from the plugin’s output, mitigating the CWE‑79 vulnerability until a patch is available.
  • If you cannot uninstall or update the plugin, disable or remove the Slider Revolution module from the page templates or replace it with an alternative plugin to eliminate the XSS vector.

Generated by OpenCVE AI on July 21, 2026 at 11:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 04 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Themepunch
Themepunch slider Revolution
Wordpress
Wordpress wordpress
Vendors & Products Themepunch
Themepunch slider Revolution
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemePunch Slider Revolution allows Reflected XSS. This issue affects Slider Revolution: from 7.0.0 through 7.0.16.
Title WordPress Slider Revolution plugin 7.0.0-7.0.16 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Themepunch Slider Revolution
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T12:21:24.825Z

Reserved: 2026-06-25T08:03:42.567Z

Link: CVE-2026-57678

cve-icon Vulnrichment

Updated: 2026-07-02T12:21:06.320Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T11:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')