Stored Cross-Site Scripting in Responsive and Swipe Slider for WordPress
CVE-2025-14721

5.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 December 2025

What is CVE-2025-14721?

The Responsive and Swipe Slider plugin for WordPress is susceptible to Stored Cross-Site Scripting due to a failure in properly sanitizing user inputs and escaping outputs in its rsSlider shortcode. This vulnerability allows attackers with contributor-level access or higher to inject malicious scripts into pages, which execute when users visit the compromised pages. All versions up to and including 1.0.2 are affected, posing significant security risks for WordPress users leveraging this plugin.

Affected Version(s)

RESPONSIVE AND SWIPE SLIDER! * <= 1.0.2

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bhumividh Treloges
.
CVE-2025-14721 : Stored Cross-Site Scripting in Responsive and Swipe Slider for WordPress