Description
The WP Airbnb Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.2 due to insufficient URL validation that allows users to pull in a malicious HTML file. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Published: 2025-11-07
Score: 4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The WP Airbnb Review Slider plugin for WordPress is vulnerable to stored Cross‑Site Scripting in all releases up to version 4.2. The flaw arises from insufficient validation of URLs entered into the plugin’s administration settings, allowing an administrator or higher to upload a malicious HTML file that is then stored and served to site visitors. When a user views a page containing the injected content, the embedded script executes in that user’s browser, which can lead to session hijacking, cookie theft, defacement, or other client‑side attacks. This weakness is identified as CWE‑79.

Affected Systems

The affected product is the WordPress plugin WP Airbnb Review Slider developed by jgwhite33. All plugin versions 4.2 and earlier are vulnerable. The vulnerability only manifests on multisite installations where the WordPress option unfiltered_html has been disabled, meaning that sites using the default filtering rules are at risk.

Risk and Exploitability

The CVSS score of 4 indicates a moderate severity, while the EPSS score of less than 1 % shows a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access with administrator‑level permissions, and the injection is performed through the plugin’s own settings interface. Once the malicious script is stored, it is executed automatically on any page that includes the injected URL. Although the likelihood of widespread exploitation is low at present, the impact of a successful XSS can be significant, especially on sites that rely on the plugin for interactive displays.

Generated by OpenCVE AI on April 22, 2026 at 00:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WP Airbnb Review Slider to version 4.3 or newer, which removes the vulnerable URL validation path.
  • If an upgrade cannot be performed immediately, replace the plugin’s external‑URL feature by removing or disabling the option for administrators until remediation is possible.
  • Apply a web‑application firewall rule that blocks execution of injected JavaScript or sanitizes stored URLs in the plugin’s database entries.

Generated by OpenCVE AI on April 22, 2026 at 00:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Nov 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Nov 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Jgwhite33
Jgwhite33 wp Thumbtack Review Slider
Wordpress
Wordpress wordpress
Vendors & Products Jgwhite33
Jgwhite33 wp Thumbtack Review Slider
Wordpress
Wordpress wordpress

Fri, 07 Nov 2025 05:45:00 +0000

Type Values Removed Values Added
Description The WP Airbnb Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.2 due to insufficient URL validation that allows users to pull in a malicious HTML file. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Title WP Airbnb Review Slider <= 4.2 - Authenticated (Admin+) Stored Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Jgwhite33 Wp Thumbtack Review Slider
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:56:37.713Z

Reserved: 2025-10-30T16:30:34.365Z

Link: CVE-2025-12520

cve-icon Vulnrichment

Updated: 2025-11-07T13:24:11.812Z

cve-icon NVD

Status : Deferred

Published: 2025-11-07T06:15:33.013

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-12520

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T00:45:04Z

Weaknesses