Impact
The Master Slider WordPress plugin through version 3.11.2 fails to sanitize and escape certain shortcode attributes before inserting them into an inline script block. Attackers with the Contributor role or higher can embed malicious script content into these attributes, resulting in a stored cross‑site scripting vulnerability that is executed in the browsers of any user who views the affected post. The injected code can hijack sessions, deface the site, or exfiltrate sensitive data accessed by the browsing user.
Affected Systems
All installations of the Master Slider WordPress plugin with version numbers up to and including 3.11.2 are affected. No later version or patch is listed in the input, and no vendor details beyond the plugin name are provided.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity for this stored cross‑site scripting vulnerability, and the EPSS score is < 1%, suggesting that exploitation is unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation. The likely attack vector is an authorized Contributor or higher user creating or editing a post that contains the vulnerable ms_slider shortcode. The exploit condition requires the malicious shortcode to be stored and the post viewed thereafter; no additional network or privilege escalation is necessary beyond the post creation authority.
OpenCVE Enrichment