Impact
Subscriber Cross Site Scripting in Slider Pro allows an attacker to embed malicious script into content rendered by the plugin. The flaw occurs because the plugin does not properly sanitize user‑supplied data, enabling arbitrary JavaScript to execute in the victim’s browser. The vulnerability is a classic CWE‑79 injection weakness.
Affected Systems
The vulnerable product is the Slider Pro plugin for WordPress from bqworks. All releases 4.8.13 and earlier are affected; any WordPress site that has the plugin at one of those versions is impacted. Updating the plugin to a version 4.8.14 or newer removes the vulnerability.
Risk and Exploitability
Based on the description, it is inferred that the attack vector is user‑supplied content in the slider fields. The CVSS score of 7.1 indicates a high severity level. The EPSS score is below 1 %, so current exploitation rates are low but not negligible. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it by injecting script into slider content that is rendered by the plugin, causing the malicious code to run in the context of the victim’s browser.
OpenCVE Enrichment