Impact
The Slider, Gallery, and Carousel by MetaSlider plugin is vulnerable to a stored cross‑site scripting flaw caused by the unsanitized and unescaped 'delay' post meta setting. Authenticated users with author or higher privileges can inject arbitrary JavaScript by submitting the value of this parameter through XML‑RPC or the WordPress admin. Each time a page containing the injected slide is viewed, the malicious script runs in the victim’s browser, enabling theft of session cookies, defacement, or redirection to malicious sites.
Affected Systems
All installations of the MetaSlider plugin for WordPress up to and including version 3.111.0. The plugin’s ml-slider custom post type and ml-slider_settings meta key lack capability restrictions, allowing any author‑level user to set the vulnerable delay property.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack requires authenticated author or higher access and exploitation is limited to sites where XML‑RPC is enabled or where the author can create slides. Due to the need for legitimate credentials, the risk is lower than for unauthenticated but still significant for multi‑user WordPress sites.
OpenCVE Enrichment