Stored Cross-Site Scripting Vulnerability in MetaSlider Plugin for WordPress
CVE-2026-18400

6.4MEDIUM

What is CVE-2026-18400?

The MetaSlider plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability caused by inadequate input sanitization and output escaping for the 'delay' Post Meta Setting. This flaw affects all versions up to and including 3.111.0, allowing authenticated users with custom-level access to inject malicious scripts into pages. When a user accesses an affected page, the injected scripts execute, potentially compromising user security. The issue arises because the ml-slider custom post type lacks necessary capability restrictions, and the ml-slider_settings meta key is unprotected, granting Author-level users the ability to insert harmful values via XML-RPC custom_fields when creating ml-slider posts.

Affected Version(s)

Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider 0 <= 3.111.0

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

haofanjiukunle
.