PatchSiren

metaslider CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM metaslider CVE published 2026-08-06

CVE-2026-18400

The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'delay' Post Meta Setting in all versions up to, and including, 3.111.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages [truncated]

CRITICAL MetaSlider CVE published 2026-06-15

CVE-2026-39465

A critical vulnerability, CVE-2026-39465, was discovered in the Responsive Slider by MetaSlider plugin for WordPress, version 3.106.0 and earlier. This vulnerability allows for remote code execution (RCE) and has a CVSS score of 9.1, indicating a high severity level. The vulnerability was published on June 15, 2026, and last modified on the same day.