Impact
The Serious Slider WordPress plugin is vulnerable to a stored cross‑site scripting flaw that allows an authenticated user with at least contributor level to inject arbitrary JavaScript via the 'theme' attribute in the shortcode. When the malicious code is stored, it executes automatically whenever any user opens a page containing the injected subtitle, potentially allowing session hijacking, credential theft, or defacement. The weakness arises from insufficient input validation and output escaping, meeting the criteria of CWE‑79.
Affected Systems
WordPress sites running the Serious Slider plugin version 1.4.0 or earlier, provided by Cryout‑Creations, are affected. Any site that has deployed these versions and permits contributors to add or edit slides is at risk.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.4, indicating moderate severity. EPSS data is unavailable, and the issue is not listed in CISA’s KEV catalog. Exploitation requires authentication but is otherwise straightforward: a contributor can edit slide content, inject the malicious attribute, and the script runs for all visitors. Likely attack vectors involve compromised contributor credentials or brute‑force access to an admin account that can assign contributor rights.
OpenCVE Enrichment