Metaslider · Slider · CVE-2026-18400
**Name of the Vulnerable Software and Affected Versions**
Slider, Gallery, and Carousel by MetaSlider versions prior to 3.111.1
**Description**
Insufficient input sanitization and output escaping allow authenticated attackers with Author-level access and above to perform Stored Cross-Site Scripting. This occurs because the `ml-slider` custom post type lacks custom capability restrictions and the `ml-slider settings` meta key is unprotected. An attacker can inject arbitrary web scripts by setting a malicious value for the `delay` parameter via XML-RPC `custom fields` when creating an `ml-slider` post. These scripts execute whenever a user accesses the affected page.
**Recommendations**
Update to a version newer than 3.111.0.