Reflected Cross-Site Scripting in Wp Responsive Thumbnail Slider Plugin for WordPress
CVE-2026-18344

6.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 August 2026

What is CVE-2026-18344?

The Wp Responsive Thumbnail Slider plugin for WordPress contains a vulnerability due to inadequate input sanitization and output escaping within the responsive_thumbnail_image_management() function. Specifically, the plugin directly echoes the user-supplied 'id' parameter into a double-quoted HTML attribute without proper escaping. This oversight permits unauthenticated attackers to execute arbitrary web scripts on the website by cleverly deceiving users into clicking malicious links. The flaw exists in versions before 1.1.53, making it critical for users to update promptly to mitigate the risk of exploitation.

Affected Version(s)

Responsive Thumbnail Slider 0 < 1.1.53

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.