Stored Cross-Site Scripting in Master Slider Plugin for WordPress
CVE-2025-5291
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 June 2025
What is CVE-2025-5291?
The Master Slider plugin for WordPress is susceptible to a stored cross-site scripting vulnerability due to insufficient sanitization of user input in the masterslider_pb and ms_slide shortcodes. This flaw allows authenticated users with contributor-level access and higher to inject malicious web scripts into WordPress pages. When users access these compromised pages, the injected scripts execute, potentially compromising user data and website integrity.
Affected Version(s)
Master Slider – Responsive Touch Slider * <= 3.10.8