JavaScript Injection Vulnerability in Post Grid, Slider & Carousel Ultimate Plugin by WordPress
CVE-2026-16260

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-16260?

The Post Grid, Slider & Carousel Ultimate plugin for WordPress prior to version 1.8.1 is susceptible to a JavaScript injection vulnerability. This flaw arises from the plugin's failure to properly sanitize and escape specific custom post type settings prior to rendering them in HTML attributes on the admin edit screen. As a result, contributors and users with higher roles can exploit this vulnerability by injecting malicious JavaScript. When an administrator accesses the affected settings, the injected script executes within their session, posing significant security risks such as unauthorized access or data manipulation.

Affected Version(s)

Post Grid, Slider & Carousel Ultimate 0 < 1.8.1

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yaswanth Reddy Sunkara
WPScan
.