PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-7636 smub CVE debrief

The Slider by Soliloquy – Responsive Image Slider for WordPress plugin is vulnerable to Sensitive Information Exposure. Authenticated attackers with subscriber-level access can extract draft slider metadata, including unpublished media URLs, captions, and slider configuration authored by administrators or editors. This vulnerability has a CVSS score of 4.3 and is considered Medium severity. Administrators and users of the Slider by Soliloquy plugin should be aware of this vulnerability and take necessary precautions.

Vendor
smub
Product
Slider by Soliloquy – Responsive Image Slider for WordPress
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-22
Original CVE updated
2026-07-23
Advisory published
2026-05-22
Advisory updated
2026-07-23

Who should care

Administrators and users of the Slider by Soliloquy plugin, especially those with subscriber-level access or above, should be aware of this vulnerability. They should review their installations, restrict access to sensitive metadata, and monitor for suspicious activity related to slider metadata access.

Technical summary

The Slider by Soliloquy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.1 via the map_meta_cap. This allows authenticated attackers with subscriber-level access and above to extract draft slider metadata including unpublished media URLs, captions, and slider configuration authored by administrators or editors. The vulnerability has a CVSS score of 4.3, indicating Medium severity.

Defensive priority

Medium priority due to the CVSS score of 4.3 and the potential for information exposure.

Recommended defensive actions

  • Update the Slider by Soliloquy plugin to the latest version.
  • Restrict access to sensitive metadata for users with subscriber-level access.
  • Monitor for suspicious activity related to slider metadata access.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record was published on 2026-05-22T09:16:32.437Z and was last modified on 2026-07-23T16:10:00.137Z. The NVD entry is currently Deferred. Evidence is limited to public CVE and NVD information. Defenders should verify affected product deployments, review official advisories, and plan for vendor-supported updates or mitigations.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-22T09:16:32.437Z and has not been modified since then. The NVD entry is currently Deferred.