Description
The Wonka Slide plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `list_class` shortcode in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-02-07
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting (XSS)
Action: Apply Patch
AI Analysis

Impact

The Wonka Slide plugin for WordPress contains a stored cross‑site scripting flaw (CWE‑79) within its `list_class` shortcode. The plugin fails to properly sanitize or escape user‑supplied attributes, which allows attackers with contributor‑level access or higher to inject arbitrary JavaScript into the shortcode. When a visitor loads a page containing the malicious shortcode, the script runs in the victim’s browser and can hijack sessions, deface content, or execute additional malicious actions.

Affected Systems

WordPress installations that host the Wonka Slide plugin from vendor mrlister1, specifically any version up to and including 1.3.3. The vulnerability applies to sites that permit contributors to create or edit the `list_class` shortcode, as the flaw is triggered by manipulating that shortcode’s attributes.

Risk and Exploitability

The base CVSS score of 6.4 indicates moderate severity, while the EPSS score of less than 1 % suggests few detected exploitation attempts. The vulnerability is not listed in the CISA KEV catalog. Attackers must first be authenticated as contributors or higher, then use the plugin’s administrative interface to insert malicious attributes into the shortcode. Although the attack surface is restricted to privileged users, any compromise of contributor access can lead to session hijacking or defacement of the site.

Generated by OpenCVE AI on April 15, 2026 at 18:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Wonka Slide plugin to the newest available release to remove the stored XSS flaw.
  • If an upgrade cannot be applied immediately, restrict contributor and higher privileges from using the `list_class` shortcode or disable that shortcode altogether until the vulnerability is patched.
  • Limit WordPress contributor permissions to trusted accounts only and monitor for unusual usage of the shortcode, ensuring that only authorized users can inject content.

Generated by OpenCVE AI on April 15, 2026 at 18:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 12 Feb 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Feb 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Sat, 07 Feb 2026 08:45:00 +0000

Type Values Removed Values Added
Description The Wonka Slide plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `list_class` shortcode in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Wonka Slide <= 1.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:32:27.483Z

Reserved: 2026-01-29T12:41:26.535Z

Link: CVE-2026-1613

cve-icon Vulnrichment

Updated: 2026-02-11T15:37:20.716Z

cve-icon NVD

Status : Deferred

Published: 2026-02-07T09:16:00.730

Modified: 2026-04-15T00:35:42.020

Link: CVE-2026-1613

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T18:45:11Z

Weaknesses