Stored Cross-Site Scripting Vulnerability in Master Slider WordPress Plugin
CVE-2026-14844

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-14844?

The Master Slider plugin for WordPress, up to version 3.11.2, contains a vulnerability due to improper sanitization and escaping of shortcode attributes. This weakness permits users with the Contributor role and above to execute Stored Cross-Site Scripting (XSS) attacks when an affected post is viewed. No patched version is currently available. Site administrators are advised to limit the Contributor role's permissions to trusted users or deactivate the plugin until a fix is released. Alternatively, users can implement shortcode restrictions to mitigate risks without removing the plugin.

Affected Version(s)

Master Slider 0 <= 3.11.2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

WEI HSIANG WANG
WPScan
.