WordPress Plugin Vulnerabilities

Slick Slider < 0.5.3 - Contributor+ Stored XSS via Gallery Shortcode

Description

The plugin does not sanitize and escape a shortcode attribute value before outputting it in an HTML attribute, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute when a user views the affected post.

Proof of Concept

Affects Plugins

Fixed in 0.5.3

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
testoun
Submitter
testoun
Verified
Yes

Timeline

Publicly Published
2026-07-31 (about 27 days ago)
Added
2026-07-24 (about 1 month ago)
Last Updated
2026-07-31 (about 27 days ago)

Other