Slider, Gallery, and Carousel by MetaSlider <= 3.98.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via aria-label Parameter
Published Jun 14, 2025
6.4
MEDIUMCVSS 3.1
EPSS 0.26%
Description
The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘aria-label’ parameter in all versions up to, and including, 3.98.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected products
- Vendor Metaslider Product Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider Defaultunaffected
Affected
- ≥ 0, ≤ 3.98.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Metaslider | Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider | unaffected | Affected
|
- < 3.99.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-18336 Advisory
- https://plugins.trac.wordpress.org/browser/ml-slider/tags/3.98.0/assets/metaslider/script.js#L11 Product
- https://plugins.trac.wordpress.org/changeset/3309932/ml-slider/tags/3.99.0/assets/metaslider/script.js Patch
- https://wordpress.org/plugins/ml-slider/#developers Product
- https://www.wordfence.com/threat-intel/vulnerabilities/id/0e6492e5-a506-4d77-96d2-08f700b6ee76?source=cve Third Party Advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data