Description
Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions.
Published: 2026-08-18
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery flaw that allows any visitor to send a forged request to the Slider by 10Web plugin without authentication. The flaw permits deletion of arbitrary files on the web server, which can lead to loss of data, defacement, or loss of service availability for the affected WordPress site. The weakness is identified as CWE‑352 and manifests as insufficient CSRF protection in request handling logic.

Affected Systems

The defect exists in the 10Web:Slider by 10Web WordPress plugin for all releases up to and including version 1.2.62. No additional or patched versions are mentioned in the supplied data.

Risk and Exploitability

The CVSS score of 7.4 indicates high severity. Because authentication is not required, any visitor can trigger the exploit, dramatically increasing risk. No EPSS data is available, but the lack of an authentication barrier and the potential for complete file deletion make this vulnerability highly dangerous. It is not listed in CISA’s KEV catalog, but administrators should treat it as a significant business risk.

Generated by OpenCVE AI on August 18, 2026 at 17:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Slider by 10Web plugin to the latest version supplied by 10Web if a patch has been released.
  • If upgrading is not an option, disable or delete the plugin to eliminate the vulnerable functionality and reduce attack surface.
  • Restrict file permissions on the WordPress uploads directory to prevent unauthorized deletions from occurring.

Generated by OpenCVE AI on August 18, 2026 at 17:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared 10web
10web sliderby10web
Wordpress
Wordpress wordpress
Vendors & Products 10web
10web sliderby10web
Wordpress
Wordpress wordpress

Tue, 18 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions.
Title WordPress Slider by 10Web plugin <= 1.2.62 - CSRF to Arbitrary File Deletion vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H'}


Subscriptions

10web Sliderby10web
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T19:48:23.081Z

Reserved: 2026-07-27T14:00:34.306Z

Link: CVE-2026-66635

cve-icon Vulnrichment

Updated: 2026-08-18T19:40:09.959Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T15:16:58.087

Modified: 2026-08-20T12:48:31.843

Link: CVE-2026-66635

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:00:12Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)