PT-2026-79514 · WordPress · Slider Hero With Video Background
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Slider Hero with Video Background, Animation WordPress plugin versions prior to 9.1.3
Description
Lack of authorization and nonce checks on two request handlers, combined with a failure to escape a stored setting before output, allows unauthenticated users to perform a Stored Cross-Site Scripting (XSS) attack. This occurs when malicious JavaScript is stored and subsequently executed in the context of an administrator accessing the plugin admin area or any visitor viewing a page that embeds a slider.
Recommendations
Update Slider Hero with Video Background, Animation WordPress plugin to version 9.1.3 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Slider Hero With Video Background