WordPress Plugin Vulnerabilities

Post Slides <= 1.0.1 - Contributor+ Local File Inclusion

Description

The plugin does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as with contributor or higher roles to perform LFI attacks

Proof of Concept

Affects Plugins

No known fix

References

Classification

Type
LFI
OWASP top 10
CWE

Miscellaneous

Original Researcher
Khaled Alenazi (Nxploited)
Submitter
Khaled Alenazi (Nxploited)
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-01-16 (about 21 days ago)
Added
2026-01-09 (about 28 days ago)
Last Updated
2026-01-09 (about 28 days ago)

Other