Impact
The vulnerability stems from insufficient sanitization of the 'data-href' attribute in the Custom HTML block of Smart Slider 3. This allows an authenticated user with contributor or higher privileges to inject arbitrary JavaScript into slide content that is stored in the database. When any visitor loads a slide containing the malicious payload, the script executes in the victim's browser, enabling session hijacking, cookie theft, defacement or downstream attacks such as phishing.
Affected Systems
All installations of the Smart Slider 3 WordPress plugin that are at or below version 3.5.1.38 are affected. This includes every WordPress site that has not upgraded past this version. The issue is not tied to a particular WordPress theme or configuration beyond the presence of the plugin.
Risk and Exploitability
The CVSS v3 score of 6.4 categorises this as medium severity. Allied with the requirement for authenticated contributor access, the attack surface is limited to who the site owner allows to edit slides. However, once the malicious script is stored, it will affect every user that views the compromised page, and the exploit is completely automated at the point of script injection. Because the EPSS score is not available, we cannot quantify current exploitation prevalence, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the potential for cross‑site data theft remains significant.
OpenCVE Enrichment