Stored Cross-Site Scripting Vulnerability in MetaSlider Plugin for WordPress
CVE-2026-18400
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 6 August 2026
What is CVE-2026-18400?
The MetaSlider plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability caused by inadequate input sanitization and output escaping for the 'delay' Post Meta Setting. This flaw affects all versions up to and including 3.111.0, allowing authenticated users with custom-level access to inject malicious scripts into pages. When a user accesses an affected page, the injected scripts execute, potentially compromising user security. The issue arises because the ml-slider custom post type lacks necessary capability restrictions, and the ml-slider_settings meta key is unprotected, granting Author-level users the ability to insert harmful values via XML-RPC custom_fields when creating ml-slider posts.
Affected Version(s)
Slider, Gallery, and Carousel by MetaSlider β Image Slider, Video Slider 0 <= 3.111.0