Description
Cross-Site Request Forgery (CSRF) vulnerability in ryscript NV Slider nv-slider allows Stored XSS.This issue affects NV Slider: from n/a through <= 1.6.
Published: 2025-01-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery flaw that allows an attacker to inject malicious script content into the NV Slider post‑insertion process, resulting in stored cross‑site scripting. The weakness is identified as CWE‑352, which enables the attacker to convey forged requests that are authenticated against the target site. The stored XSS can then execute in the browsers of any visitor who views the affected slider, potentially exfiltrating credentials, defacing content, or loading additional malware.

Affected Systems

WordPress sites that have installed the ryscript NV Slider plugin version 1.6 or earlier are affected. The product is the NV Slider plugin published by ryscript; all installations from the original release up to and including version 1.6 carry the flaw.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity vulnerability, while the EPSS score of less than 1% suggests that, although exploits are possible, they are currently unlikely to be widely deployed. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is that an attacker hosts a malicious link or page that tricks an authenticated user of the victim site into visiting it, which then submits a forged request to the NV Slider endpoint; the resulting stored script is injected into the slider content and runs for all subsequent site visitors.

Generated by OpenCVE AI on May 1, 2026 at 21:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade NV Slider to the latest release (v1.7 or newer) to remove the CSRF vulnerability.
  • If upgrading is not immediately possible, disable the NV Slider plugin and remove any slider content that may already contain malicious script.
  • Configure a web application firewall (WAF) to block CSRF tokens that do not match the expected values to reduce the window of opportunity for injection.

Generated by OpenCVE AI on May 1, 2026 at 21:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3325 Cross-Site Request Forgery (CSRF) vulnerability in Ryan Sutana NV Slider allows Stored XSS.This issue affects NV Slider: from n/a through 1.6.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Ryan Sutana NV Slider allows Stored XSS.This issue affects NV Slider: from n/a through 1.6. Cross-Site Request Forgery (CSRF) vulnerability in ryscript NV Slider nv-slider allows Stored XSS.This issue affects NV Slider: from n/a through <= 1.6.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 17 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Ryan Sutana NV Slider allows Stored XSS.This issue affects NV Slider: from n/a through 1.6.
Title WordPress NV Slider plugin <= 1.6 - CSRF to Stored Cross-Site Scripting vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:16.427Z

Reserved: 2025-01-16T11:27:51.185Z

Link: CVE-2025-23661

cve-icon Vulnrichment

Updated: 2025-01-17T17:20:19.328Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T20:15:43.037

Modified: 2026-06-17T08:56:11.090

Link: CVE-2025-23661

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T21:15:25Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)