← Vulnerability feed

Vulnerability record · CVE-2014-9735 · published 30 June 2015

CVE-2014-9735: WordPress Slider Revolution and Showbiz Pro missing AJAX access control

Themepunch · Showbiz Pro

The ThemePunch Slider Revolution plugin before 3.0.96 and Showbiz Pro 1.7.1 and earlier for WordPress fail to restrict access to administrator AJAX functionality. Unauthenticated remote attackers can reach privileged actions such as update_plugin, delete_slider, and slider create/update/import/export. This is a high-severity access control flaw that enables arbitrary file upload and execution on affected sites.

7.5 CVSS 2.0 High EPSS 76% · top 0.5% CWE-264 · Permissions and access controls
7.5CVSS 2.0 base score
76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
14References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier for Wordpress does not properly restrict access to administrator AJAX functionality, which allows remote attackers to (1) upload and execute arbitrary files via an update_plugin action; (2) delete arbitrary sliders via a delete_slider action; and (3) create, (4) update, (5) import, or (6) export arbitrary sliders via unspecified vectors.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution via arbitrary file upload with public exploit code and very high EPSS, though not in KEV.

What it is

The ThemePunch Slider Revolution plugin before 3.0.96 and Showbiz Pro 1.7.1 and earlier for WordPress fail to restrict access to administrator AJAX functionality. Unauthenticated remote attackers can reach privileged actions such as update_plugin, delete_slider, and slider create/update/import/export. This is a high-severity access control flaw that enables arbitrary file upload and execution on affected sites.

Impact

An attacker can upload and execute arbitrary files, achieving remote code execution on the web server, and can also delete, create, update, import, or export arbitrary sliders. This gives full compromise of the WordPress installation and its host.

Attack surface

Reached over the network through the plugin's AJAX endpoints; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. Any internet-exposed WordPress site running an affected plugin version is directly reachable.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.757 probability, 99.5th percentile) and multiple references are tagged Exploit, including public disclosures and a report of massive WordPress compromise. Exploitation is publicly documented and widely attempted.

What to do

  • Update Slider Revolution to 3.0.96 or later and Showbiz Pro beyond 1.7.1; if the vendor no longer supports the version, remove or replace the plugin.
  • Apply the vendor patch or the community revsliderpatch.php if an immediate upgrade is not possible.
  • Remove or disable unused slider plugins and themes that bundle revslider.
  • Restrict access to wp-admin and plugin AJAX endpoints by IP or authentication where feasible.
  • Audit the web root for unexpected PHP files and restore from a known clean backup if compromise is suspected.

Detection

  • Monitor web server and WordPress logs for POST requests to admin-ajax.php or plugin endpoints with actions update_plugin, delete_slider, or slider import/export from unauthenticated clients.
  • Alert on new or modified PHP files in wp-content/plugins, wp-content/uploads, and the web root.
  • Hunt for outbound connections or dropped webshells consistent with the SoakSoak mass compromise campaign.
  • Inventory installed plugin versions and flag any Slider Revolution below 3.0.96 or Showbiz Pro 1.7.1 and earlier.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-9735 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2015-9499Themepunch showbiz pro unrestricted file upload vulnerabilityThe Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.EPSS 16%8.8CVE-2024-34444Themepunch slider revolution missing authorization vulnerabilityMissing Authorization vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a before 6.7.0.EPSS 0.33%8.8CVE-2023-6528Themepunch slider revolution deserialization of untrusted data vulnerabilityThe Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when i…EPSS 1.4%8.8CVE-2023-47784Themepunch slider revolution unrestricted file upload vulnerabilityUnrestricted Upload of File with Dangerous Type vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a thro…EPSS 0.69%8.8CVE-2023-2359Themepunch slider revolution code injection vulnerabilityThe Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may…EPSS 2.5%5.4CVE-2024-8107Themepunch slider revolution cross-site scripting vulnerabilityThe Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.…EPSS 0.32%5.4CVE-2024-34443Themepunch slider revolution cross-site scripting vulnerabilityImproper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemePunch OHG Slider Revolution allows …EPSS 0.28%5.4CVE-2024-4637Themepunch slider revolution cross-site scripting vulnerabilityThe Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.7.10 due to insuffici…EPSS 0.26%

Source: NIST National Vulnerability Database (record CVE-2014-9735), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.