Description
The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-href' parameter in all versions up to, and including, 3.5.1.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-09-30
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch Immediately
AI Analysis

Impact

The vulnerability stems from insufficient sanitization of the 'data-href' attribute in the Custom HTML block of Smart Slider 3. This allows an authenticated user with contributor or higher privileges to inject arbitrary JavaScript into slide content that is stored in the database. When any visitor loads a slide containing the malicious payload, the script executes in the victim's browser, enabling session hijacking, cookie theft, defacement or downstream attacks such as phishing.

Affected Systems

All installations of the Smart Slider 3 WordPress plugin that are at or below version 3.5.1.38 are affected. This includes every WordPress site that has not upgraded past this version. The issue is not tied to a particular WordPress theme or configuration beyond the presence of the plugin.

Risk and Exploitability

The CVSS v3 score of 6.4 categorises this as medium severity. Allied with the requirement for authenticated contributor access, the attack surface is limited to who the site owner allows to edit slides. However, once the malicious script is stored, it will affect every user that views the compromised page, and the exploit is completely automated at the point of script injection. Because the EPSS score is not available, we cannot quantify current exploitation prevalence, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the potential for cross‑site data theft remains significant.

Generated by OpenCVE AI on September 30, 2026 at 12:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Smart Slider 3 to a version newer than 3.5.1.38 once the vendor releases a fix
  • Restrict contributor and higher level permissions to trusted administrators only, or remove contributor access
  • Remove or sanitise custom HTML blocks that use the data‑href attribute until a patch is applied
  • Apply web application firewall rules to filter out malicious script payloads in data‑href attributes

Generated by OpenCVE AI on September 30, 2026 at 12:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-href' parameter in all versions up to, and including, 3.5.1.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Smart Slider 3 <= 3.5.1.38 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-href' Attribute in Custom HTML Block
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-30T15:28:11.221Z

Reserved: 2026-07-06T15:15:58.174Z

Link: CVE-2026-14876

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-30T08:16:32.840

Modified: 2026-09-30T16:17:11.480

Link: CVE-2026-14876

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T12:15:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')