Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemePunch Slider Revolution allows Reflected XSS.

This issue affects Slider Revolution: from 7.0.0 through 7.0.16.
Published: 2026-07-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper Neutralization of Input During Web Page Generation, also known as Cross‑Site Scripting (XSS), is present in the ThemePunch Slider Revolution plugin for WordPress. The flaw allows an attacker to inject malicious scripts that are rendered in the browsers of visitors when the plugin processes user‑supplied input without adequate escaping. The resulting impact is that any attacker who can embed crafted input in a request—typically through a URL parameter or form field—can cause arbitrary script execution in the victim’s browser, which may lead to session hijacking, defacement, or phishing within the context of the affected site.

Affected Systems

The vulnerability is confined to the WordPress Slider Revolution plugin versions 7.0.0 through 7.0.16. Any WordPress installation that has one of these releases installed is susceptible. The flaw is not limited to the core WordPress platform but specifically targets the Slider Revolution component provided by ThemePunch.

Risk and Exploitability

The CVSS score of 7.1 classifies this as high severity. An EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a reflected XSS that can be triggered by an attacker sending a crafted request containing malicious input—such as a malicious URL or form submission—to a site that hosts the affected plugin. No authentication or elevated privileges are required to exploit the weakness.

Generated by OpenCVE AI on August 1, 2026 at 21:25 UTC.

Remediation

Vendor Solution

Update the WordPress Slider Revolution Plugin to the latest available version (at least 7.1.0).


OpenCVE Recommended Actions

  • Update the WordPress Slider Revolution plugin to the latest available version (at least 7.1.0).
  • If an immediate update is not feasible, disable or remove the Slider Revolution module from all page templates, or uninstall the plugin entirely to eliminate the XSS vector.
  • If disabling is not possible, implement a Web Application Firewall rule or enforce a Content Security Policy that blocks inline script execution from the plugin’s output, mitigating the risk until a patch is applied.

Generated by OpenCVE AI on August 1, 2026 at 21:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 04 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Themepunch
Themepunch slider Revolution
Wordpress
Wordpress wordpress
Vendors & Products Themepunch
Themepunch slider Revolution
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemePunch Slider Revolution allows Reflected XSS. This issue affects Slider Revolution: from 7.0.0 through 7.0.16.
Title WordPress Slider Revolution plugin 7.0.0-7.0.16 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Themepunch Slider Revolution
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T12:21:24.825Z

Reserved: 2026-06-25T08:03:42.567Z

Link: CVE-2026-57678

cve-icon Vulnrichment

Updated: 2026-07-02T12:21:06.320Z

cve-icon NVD

Status : Deferred

Published: 2026-07-02T12:17:38.467

Modified: 2026-07-02T13:58:23.330

Link: CVE-2026-57678

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T21:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')