Impact
The Simple SEO Slideshow WordPress plugin contains a stored cross‑site scripting vulnerability caused by insufficient input sanitization and output escaping in shortcode attributes. An authenticated user with contributor role or higher can insert malicious script payloads that are saved to the database. When any visitor loads a page containing the affected slideshow, the injected scripts execute in the visitor’s browser, enabling unauthorized access to session data, defacement, or further malicious activity. The weakness is classified as CWE‑79.
Affected Systems
All installations of the Simple SEO Slideshow plugin up to and including version 1.2.8 are affected. Any WordPress site that has installed this plugin and assigns contributor or higher roles to users is vulnerable. No other WordPress core components are impacted by this specific flaw.
Risk and Exploitability
The CVSS v3 score of 6.4 indicates medium severity. EPSS data is not available, and the issue is not listed in the CISA KEV catalog, suggesting no publicly known exploitation at the time of analysis. The primary attack vector requires an authenticated user with contributor access, a role that is commonly available on operational sites. Based on the description, it is inferred that contributor roles are usually granted in typical WordPress deployments, so the opportunity for exploitation is realistic. Once a payload is injected, it persists until the content is edited or the plugin is removed, enabling all subsequent page views – including those by administrators – to be affected.
OpenCVE Enrichment