Stored Cross-Site Scripting Vulnerability in Master Slider WordPress Plugin
CVE-2026-14844
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 20 September 2026
Badges
What is CVE-2026-14844?
The Master Slider plugin for WordPress, up to version 3.11.2, contains a vulnerability due to improper sanitization and escaping of shortcode attributes. This weakness permits users with the Contributor role and above to execute Stored Cross-Site Scripting (XSS) attacks when an affected post is viewed. No patched version is currently available. Site administrators are advised to limit the Contributor role's permissions to trusted users or deactivate the plugin until a fix is released. Alternatively, users can implement shortcode restrictions to mitigate risks without removing the plugin.
Affected Version(s)
Master Slider 0 <= 3.11.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.