CVE-2026-66635

WordPress Slider by 10Web plugin <= 1.2.62 - CSRF to Arbitrary File Deletion vulnerability

Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions.


We have discovered 4,635 live websites that are affected by CVE-2026-66635.

Run a Free Instant Scan




Affected Software

Product  Slider Wd
Category Wordpress Plugins
Vulnerable Domains4,635 live websites (77% of Slider Wd install base)
Vulnerable Versions
  • from 0 through 1.2.62
Vulnerable Versions Count165 versions ( 66% of all versions)


Common Weakness Enumeration

CWE-352 Cross-Site Request Forgery (CSRF)



Details

  • Published - Aug 18, 2026
  • Updated - Aug 18, 2026

Credits

  • Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-66635
United States1,303 websites



Germany560 websites
France262 websites
Italy258 websites
GB242 websites
Netherlands184 websites
Poland175 websites
Russia145 websites
Japan116 websites
Brazil96 websites

Website Distribution by TLD

Number of websites using CVE-2026-66635
.com1,731 websites
.de378 websites
.org289 websites
.nl172 websites
.it169 websites
.co.uk145 websites
.pl133 websites
.net118 websites
.fr115 websites
.ru114 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-66635

Top websites that are affected by CVE-2026-66635. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.org United States***,***
********.nl Netherlands***,***
****************.nl Netherlands***,***
************.com United States***,***
********.ma Slovakia***,***
**************.com United States***,***
*******.com United States***,***
************.com United States***,***
****************.org United States***,***
****************.org United States***,***
See full domain list

FAQ

CVE-2026-66635 is Cross-Site Request Forgery (CSRF) in Slider Wd
A total of 4,635 websites have been identified as vulnerable to CVE-2026-66635, based on global website indexing conducted by WebTechSurvey.
The Slider Wd is affected by the CVE-2026-66635 vulnerability.
Slider Wd versions up to and including 1.2.62 are vulnerable to CVE-2026-66635.