Impact
Cross‑site scripting is disclosed in the Master Slider plugin for WordPress up to version 3.11.3. The vulnerability results from improper neutralization of input during web page generation, permitting reflected XSS. Malicious payloads injected through the plugin can execute in users’ browsers, enabling attackers to steal session cookies, deface content, or carry out other malicious actions. The weakness is identified as CWE‑79.
Affected Systems
The vulnerability affects WordPress installations that have the Master Slider plugin, Averta vendor, version 3.11.3 or earlier. No other products or versions are mentioned as affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. Externally, the EPSS score is 0.00251, indicating a very low exploitation probability, and the flaw is not listed in the CISA KEV catalog. Based on the description, the vulnerability is exploitable without authentication and is inferred to be reachable through publicly accessible pages that render the plugin’s output.
OpenCVE Enrichment