JavaScript Injection Vulnerability in Post Grid, Slider & Carousel Ultimate Plugin by WordPress
CVE-2026-16260
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 August 2026
Badges
What is CVE-2026-16260?
The Post Grid, Slider & Carousel Ultimate plugin for WordPress prior to version 1.8.1 is susceptible to a JavaScript injection vulnerability. This flaw arises from the plugin's failure to properly sanitize and escape specific custom post type settings prior to rendering them in HTML attributes on the admin edit screen. As a result, contributors and users with higher roles can exploit this vulnerability by injecting malicious JavaScript. When an administrator accesses the affected settings, the injected script executes within their session, posing significant security risks such as unauthorized access or data manipulation.
Affected Version(s)
Post Grid, Slider & Carousel Ultimate 0 < 1.8.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.