Reflected Cross-Site Scripting in Wp Responsive Thumbnail Slider Plugin for WordPress
CVE-2026-18344
6.1MEDIUM
What is CVE-2026-18344?
The Wp Responsive Thumbnail Slider plugin for WordPress contains a vulnerability due to inadequate input sanitization and output escaping within the responsive_thumbnail_image_management() function. Specifically, the plugin directly echoes the user-supplied 'id' parameter into a double-quoted HTML attribute without proper escaping. This oversight permits unauthenticated attackers to execute arbitrary web scripts on the website by cleverly deceiving users into clicking malicious links. The flaw exists in versions before 1.1.53, making it critical for users to update promptly to mitigate the risk of exploitation.
Affected Version(s)
Responsive Thumbnail Slider 0 < 1.1.53