PT-2026-79514 · WordPress · Slider Hero With Video Background

·

CVE-2026-76789

·

Published

2026-08-22

·

Updated

2026-08-23

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Slider Hero with Video Background, Animation WordPress plugin versions prior to 9.1.3
Description Lack of authorization and nonce checks on two request handlers, combined with a failure to escape a stored setting before output, allows unauthenticated users to perform a Stored Cross-Site Scripting (XSS) attack. This occurs when malicious JavaScript is stored and subsequently executed in the context of an administrator accessing the plugin admin area or any visitor viewing a page that embeds a slider.
Recommendations Update Slider Hero with Video Background, Animation WordPress plugin to version 9.1.3 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76789

Affected Products

Slider Hero With Video Background