{
  "id": "CVE-2026-86786",
  "url": "https://spydr.io/cve/CVE-2026-86786",
  "published": "2026-10-06T07:16:59.620Z",
  "modified": "2026-10-06T11:17:30.157Z",
  "score": 5.3,
  "severity": "medium",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
  "score_source": "CISA ADP",
  "epss": null,
  "epss_percentile": null,
  "exploited": false,
  "kev": null,
  "ssvc_exploitation": "none",
  "vendors": [],
  "products": [
    "Slider Pro"
  ],
  "cwes": [
    "CWE-200"
  ],
  "description": "The Slider Pro WordPress plugin through 1.0.0 does not perform any capability or authorisation check on one of its AJAX actions, allowing unauthenticated users to retrieve the title, excerpt and permalink of non-public posts, including drafts, pending, scheduled, private and trashed posts, as well as post revisions and media metadata.",
  "status": "Received",
  "score_type": "Secondary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 5.3,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "https://wpscan.com/vulnerability/0645bcad-740e-452e-9d73-3e47ddd83f8b/",
      "tags": []
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86786",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
