CVE-2025-15491
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
07/02/2026
Last modified:
09/02/2026
Description
The Post Slides WordPress plugin through 1.0.1 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as with contributor or higher roles to perform LFI attacks
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM



