Cross-site Scripting Vulnerability in GhozyLab Image Slider Widget
CVE-2026-42700
6.5MEDIUM
What is CVE-2026-42700?
The GhozyLab Image Slider Widget is vulnerable to a Cross-site Scripting (XSS) issue due to improper neutralization of input during web page generation. This vulnerability allows attackers to inject malicious scripts that can be stored and executed in the context of users who access the affected widget, potentially compromising user data and performing unauthorized actions. Affected versions include GhozyLab Image Slider Widget up to 1.1.130. It is crucial for users to update to the latest version to mitigate this risk.
Affected Version(s)
Image Slider Widget 0 <= 1.1.130