Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thiago S.F. Skitter Slideshow wp-skitter-slideshow allows Stored XSS.This issue affects Skitter Slideshow: from n/a through <= 2.5.2.
Published: 2025-03-11
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Skitter Slideshow plugin for WordPress contains an input sanitization flaw that permits an attacker to inject malicious JavaScript that is then stored and served to site visitors. This Stored XSS can lead to session hijacking, credential theft, defacement, or execution of further malicious code under the victim’s browser context. The vulnerability is categorized as CWE‑79 and directly affects the confidentiality, integrity, and availability of the site for all users who view pages rendered by the plugin.

Affected Systems

Thiago S.F.'s Skitter Slideshow plugin is vulnerable in all releases from the earliest available version through version 2.5.2 inclusive. WordPress sites that have this plugin installed and have not upgraded beyond 2.5.2 are at risk. The specific affected product name is ‘Skitter Slideshow’ and it is integrated as a WordPress plugin.

Risk and Exploitability

The CVSS score of 5.9 indicates a medium impact, while the EPSS value of less than 1 % suggests a very low probability of current exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through an administrative or content‑creation interface that allows arbitrary text to be entered into the plugin’s settings or slideshow content, where the attacker can inject malicious payloads. Once injected, the script executes when any user views the affected page, providing the attacker with the same privileges as the visitor who triggered the page load.

Generated by OpenCVE AI on May 2, 2026 at 03:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Skitter Slideshow plugin to any version newer than 2.5.2 as soon as an update is available.
  • If an upgrade cannot be performed immediately, remove or deactivate the plugin to eliminate the attack vector.
  • Deploy a web application firewall rule or a Content‑Security‑Policy header to block the execution of injected scripts on pages served by the plugin.

Generated by OpenCVE AI on May 2, 2026 at 03:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-7861 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thiago S.F. Skitter Slideshow allows Stored XSS. This issue affects Skitter Slideshow: from n/a through 2.5.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thiago S.F. Skitter Slideshow allows Stored XSS. This issue affects Skitter Slideshow: from n/a through 2.5.2. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thiago S.F. Skitter Slideshow wp-skitter-slideshow allows Stored XSS.This issue affects Skitter Slideshow: from n/a through <= 2.5.2.
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00043}

epss

{'score': 0.00066}


Wed, 12 Mar 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Mar 2025 21:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thiago S.F. Skitter Slideshow allows Stored XSS. This issue affects Skitter Slideshow: from n/a through 2.5.2.
Title WordPress Skitter Slideshow plugin <= 2.5.2 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:50.285Z

Reserved: 2025-03-11T08:09:27.024Z

Link: CVE-2025-28906

cve-icon Vulnrichment

Updated: 2025-03-12T17:22:49.328Z

cve-icon NVD

Status : Deferred

Published: 2025-03-11T21:15:47.933

Modified: 2026-04-23T15:26:34.623

Link: CVE-2025-28906

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T03:45:33Z

Weaknesses