WordPress Plugin Vulnerabilities

Slider Hero < 9.1.3 - Unauthenticated Stored XSS via Slider Type Change and Add-Slider Handlers

Description

The plugin does not have authorisation and nonce checks on two of its request handlers, and does not escape a stored setting before outputting it, allowing unauthenticated users to store malicious JavaScript which will be executed in the context of an administrator viewing the plugin's admin area, as well as any visitor of a page embedding a slider.

Proof of Concept

Affects Plugins

Fixed in 9.1.3

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Artus KG
Submitter
Artus KG
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-08-20 (about 2 days ago)
Added
2026-08-20 (about 1 day ago)
Last Updated
2026-08-21 (about 8 hours ago)

Other