PatchSiren

Master Slider CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Master Slider CVE published 2026-09-20

CVE-2026-14844

The Master Slider WordPress plugin through 3.11.2 has a Stored Cross-Site Scripting vulnerability. Users with the Contributor role and above can perform attacks that execute when the affected post is viewed. No fixed version is available. Site owners should assess exposure and take defensive actions to prevent exploitation. The vulnerability allows for Stored Cross-Site Scripting attacks due to unsanitize [truncated]