Impact
Improper neutralization of user input in the averta Master Slider plugin results in stored cross‑site scripting. A malicious script can be embedded in slider content and executed in the browsers of site visitors who view the affected slider.
Affected Systems
All WordPress sites that use the Master Slider plugin version 3.11.0 or earlier are affected. The flaw exists in the plugin’s content handling routines and is independent of site configuration.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% reflects a low likelihood of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the ability to create or modify slider content, after which the stored script is presented to users who view the slider.
OpenCVE Enrichment
EUVD