Review
Master Slider
CVE published 2026-09-20
CVE-2026-14844
The Master Slider WordPress plugin through 3.11.2 has a Stored Cross-Site Scripting vulnerability. Users with the Contributor role and above can perform attacks that execute when the affected post is viewed. No fixed version is available. Site owners should assess exposure and take defensive actions to prevent exploitation. The vulnerability allows for Stored Cross-Site Scripting attacks due to unsanitize [truncated]