Description
The Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image alt text in all versions up to, and including, 4.9.0 due to insufficient input sanitization and output escaping in the 'logo-slider' shortcode. This makes it possible for authenticated attackers, with author level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-03-21
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting that can execute arbitrary client‑side code
Action: Apply Patch
AI Analysis

Impact

The Logichunt Logo Slider plugin is vulnerable to stored Cross‑Site Scripting via the image alt text within the 'logo-slider' shortcode. An attacker who can authenticate as an author or a higher level user can enter malicious script into the alt text field. When any user views a page containing the injected content, the script executes in that user’s browser.

Affected Systems

WordPress sites running Logichunt Logo Slider version 4.9.0 or earlier are affected. The flaw is present in every release up to and including 4.9.0.

Risk and Exploitability

The CVSS score is 6.4, indicating moderate severity. The attacker must have author‑level or higher credentials to inject the payload, making internal attackers or compromised author accounts the primary threat vector. No EPSS data is available and the vulnerability is not listed in the KEV catalog, suggesting no widespread public exploitation yet, but any site that allows author‑level content creation remains at risk.

Generated by OpenCVE AI on March 21, 2026 at 07:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Logichunt Logo Slider plugin to a version newer than 4.9.0
  • Limit author‑level permissions to trusted users only
  • If an upgrade cannot be applied immediately, temporarily remove or disable the 'logo-slider' shortcode from public‑facing pages

Generated by OpenCVE AI on March 21, 2026 at 07:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 23 Mar 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 23 Mar 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Logichunt
Logichunt logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider Plugin
Wordpress
Wordpress wordpress
Vendors & Products Logichunt
Logichunt logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider Plugin
Wordpress
Wordpress wordpress

Sat, 21 Mar 2026 05:30:00 +0000

Type Values Removed Values Added
Description The Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image alt text in all versions up to, and including, 4.9.0 due to insufficient input sanitization and output escaping in the 'logo-slider' shortcode. This makes it possible for authenticated attackers, with author level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Logo Slider <= 4.9.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'logo-slider' Shortcode
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Logichunt Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider Plugin
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:17:59.061Z

Reserved: 2026-01-05T15:52:07.389Z

Link: CVE-2026-0609

cve-icon Vulnrichment

Updated: 2026-03-23T15:07:35.539Z

cve-icon NVD

Status : Deferred

Published: 2026-03-21T04:16:51.497

Modified: 2026-04-22T21:32:08.360

Link: CVE-2026-0609

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-25T14:41:43Z

Weaknesses