Impact
The YSlider plugin for WordPress lacks nonce verification on its content configuration page and fails to sanitize user input or escape output. This flaw lets an unauthenticated attacker send a forged request that, once an administrator unknowingly submits it, injects arbitrary JavaScript into a stored page. The injected script runs whenever a visitor loads the affected page, enabling front‑end code injection and potential credential theft or session hijacking.
Affected Systems
Andreaferracani YSlider, all releases up to and including version 1.1, installed on WordPress sites.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity, while the EPSS score of less than 1% suggests a low current exploitation probability and the vulnerability is not listed in CISA KEV. Exploitation requires the attacker to trick an administrator into performing a specific action; once the forged request is processed, malicious script is stored and later executed for any user who visits the compromised page.
OpenCVE Enrichment