Vulnerability record · CVE-2014-9735 · published 30 June 2015
CVE-2014-9735: WordPress Slider Revolution and Showbiz Pro missing AJAX access control
Themepunch · Showbiz Pro
The ThemePunch Slider Revolution plugin before 3.0.96 and Showbiz Pro 1.7.1 and earlier for WordPress fail to restrict access to administrator AJAX functionality. Unauthenticated remote attackers can reach privileged actions such as update_plugin, delete_slider, and slider create/update/import/export. This is a high-severity access control flaw that enables arbitrary file upload and execution on affected sites.
Description
The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier for Wordpress does not properly restrict access to administrator AJAX functionality, which allows remote attackers to (1) upload and execute arbitrary files via an update_plugin action; (2) delete arbitrary sliders via a delete_slider action; and (3) create, (4) update, (5) import, or (6) export arbitrary sliders via unspecified vectors.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
critical priorityUnauthenticated remote code execution via arbitrary file upload with public exploit code and very high EPSS, though not in KEV.
What it is
The ThemePunch Slider Revolution plugin before 3.0.96 and Showbiz Pro 1.7.1 and earlier for WordPress fail to restrict access to administrator AJAX functionality. Unauthenticated remote attackers can reach privileged actions such as update_plugin, delete_slider, and slider create/update/import/export. This is a high-severity access control flaw that enables arbitrary file upload and execution on affected sites.
Impact
An attacker can upload and execute arbitrary files, achieving remote code execution on the web server, and can also delete, create, update, import, or export arbitrary sliders. This gives full compromise of the WordPress installation and its host.
Attack surface
Reached over the network through the plugin's AJAX endpoints; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. Any internet-exposed WordPress site running an affected plugin version is directly reachable.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.757 probability, 99.5th percentile) and multiple references are tagged Exploit, including public disclosures and a report of massive WordPress compromise. Exploitation is publicly documented and widely attempted.
What to do
- Update Slider Revolution to 3.0.96 or later and Showbiz Pro beyond 1.7.1; if the vendor no longer supports the version, remove or replace the plugin.
- Apply the vendor patch or the community revsliderpatch.php if an immediate upgrade is not possible.
- Remove or disable unused slider plugins and themes that bundle revslider.
- Restrict access to wp-admin and plugin AJAX endpoints by IP or authentication where feasible.
- Audit the web root for unexpected PHP files and restore from a known clean backup if compromise is suspected.
Detection
- Monitor web server and WordPress logs for POST requests to admin-ajax.php or plugin endpoints with actions update_plugin, delete_slider, or slider import/export from unauthenticated clients.
- Alert on new or modified PHP files in wp-content/plugins, wp-content/uploads, and the web root.
- Hunt for outbound connections or dropped webshells consistent with the SoakSoak mass compromise campaign.
- Inventory installed plugin versions and flag any Slider Revolution below 3.0.96 or Showbiz Pro 1.7.1 and earlier.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-9735 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-9735), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.