Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in w1zzard Simple Text Slider simple-text-slider allows Stored XSS.This issue affects Simple Text Slider: from n/a through <= 1.0.5.
Published: 2025-09-05
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation, enabling attackers to inject malicious scripts via the Simple Text Slider plugin’s content fields. This results in a stored cross‑site scripting vector that can run arbitrary JavaScript when other users view the affected page, potentially allowing session hijacking, defacement, or redirection to phishing sites. The weakness is identified as CWE‑79, indicating inadequate input validation and output encoding.

Affected Systems

The issue affects the WordPress plugin Simple Text Slider from w1zzard, versions from the earliest available through 1.0.5 the latest release at the time of the advisory. Any WordPress site that has this plugin installed and has not applied a patch to a newer version is susceptible.

Risk and Exploitability

The CVSS score of 6.5 classifies the vulnerability as moderate severity. The EPSS score of less than 1% indicates a low probability of exploitation under current public information, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers can exploit the flaw by submitting malicious markup into the slider content, which is persisted and rendered for all visitors. The attack path is largely local with regard to site administration (i.e., any user who can add or edit slider content could inject scripts).

Generated by OpenCVE AI on April 30, 2026 at 02:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Simple Text Slider to the latest available version beyond 1.0.5, if an update exists.
  • If no patch is available, delete or deactivate the plugin to remove the vulnerable code path from the site.
  • If the plugin must remain in place, enforce strict input sanitization on the slider fields or employ a site‑wide security solution that filters out script tags before rendering the content.

Generated by OpenCVE AI on April 30, 2026 at 02:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-26897 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in w1zzard Simple Text Slider allows Stored XSS. This issue affects Simple Text Slider: from n/a through 1.0.5.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in w1zzard Simple Text Slider allows Stored XSS. This issue affects Simple Text Slider: from n/a through 1.0.5. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in w1zzard Simple Text Slider simple-text-slider allows Stored XSS.This issue affects Simple Text Slider: from n/a through <= 1.0.5.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Sun, 07 Sep 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Fri, 05 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Sep 2025 14:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in w1zzard Simple Text Slider allows Stored XSS. This issue affects Simple Text Slider: from n/a through 1.0.5.
Title WordPress Simple Text Slider Plugin <= 1.0.5 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:49.067Z

Reserved: 2025-09-05T10:50:17.983Z

Link: CVE-2025-58882

cve-icon Vulnrichment

Updated: 2025-09-05T14:31:16.679Z

cve-icon NVD

Status : Deferred

Published: 2025-09-05T14:16:05.500

Modified: 2026-06-17T09:45:13.783

Link: CVE-2025-58882

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T02:15:25Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')