Impact
The Master Slider WordPress plugin through version 3.11.2 fails to sanitize and escape certain shortcode attributes before inserting them into an inline script block. Attackers with the Contributor role or higher can embed malicious script content into these attributes, resulting in a stored cross‑site scripting vulnerability that is executed in the browsers of any user who views the affected post. The injected code can hijack sessions, deface the site, or exfiltrate sensitive data accessed by the browsing user.
Affected Systems
All installations of the Master Slider WordPress plugin with version numbers up to and including 3.11.2 are affected. No later version or patch is listed in the input, and no vendor details beyond the plugin name are provided.
Risk and Exploitability
The CVSS baseline for this issue would be considered high given its stored nature and the ability to influence content displayed to all users. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation yet. The likely attack vector is an authorized Contributor or higher user creating or editing a post that contains the vulnerable ms_slider shortcode. The exploit condition requires the user to view the post after the malicious shortcode has been stored; no additional network or privilege escalation is required beyond the post creation authority.
OpenCVE Enrichment