WordPress · Slider Hero With Video Background · CVE-2026-76789
**Name of the Vulnerable Software and Affected Versions**
Slider Hero with Video Background, Animation WordPress plugin versions prior to 9.1.3
**Description**
Lack of authorization and nonce checks on two request handlers, combined with a failure to escape a stored setting before output, allows unauthenticated users to perform a Stored Cross-Site Scripting (XSS) attack. This occurs when malicious JavaScript is stored and subsequently executed in the context of an administrator accessing the plugin admin area or any visitor viewing a page that embeds a slider.
**Recommendations**
Update Slider Hero with Video Background, Animation WordPress plugin to version 9.1.3 or later.