Sceawere
Vulnerability Detail
CVE-2026-14876UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Smart Slider 3 Stored XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.4
- Creation Date
- 2h ago
- Vendor
- nextendweb
- Product
- Smart Slider 3
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-href' parameter in all versions up to, and including, 3.5.1.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.4",
"pubDate": "2026-09-30T08:16:32.840Z",
"pubdate": "2026-09-30T08:16:32.840Z",
"executiveSummary": "The Smart Slider 3 plugin for WordPress, in versions up to and including 3.5.1.38, contains a Stored Cross-Site Scripting (XSS) vulnerability.\nThis security flaw stems from inadequate input sanitization and output escaping mechanisms within the 'data-href' parameter handling logic.\nThe vulnerability allows authenticated attackers with contributor-level privileges or higher to inject malicious JavaScript payloads into the plugin's configuration or associated content.\nOnce stored, these arbitrary scripts execute in the context of the victim's browser whenever an affected page is rendered, posing a significant risk to site integrity and user session security.\nThe primary risk implications include unauthorized access to user sessions, potential session hijacking, unauthorized actions performed on behalf of legitimate users, and the redirection of traffic to malicious destinations.\nSuccessful exploitation requires the attacker to possess at least contributor-level credentials, limiting the attack vector to insiders or compromised accounts with sufficient permissions to interact with the plugin’s interface.",
"technicalDetails": "The vulnerability is identified as a Stored Cross-Site Scripting (XSS) flaw localized within the Smart Slider 3 plugin. The root cause is the failure of the application to properly sanitize the 'data-href' attribute provided during the configuration of slider elements, combined with a failure to perform adequate output encoding when rendering these attributes in the frontend.\nThe vulnerability resides in the component responsible for processing slider settings. When a contributor-level user interacts with the plugin interface to modify slider attributes, they can supply a malicious payload within the 'data-href' parameter. Because the input is not validated against a strict allowlist (e.g., ensuring only standard URI schemes are used), the plugin accepts arbitrary characters, including those required to break out of the HTML attribute context.\nThe attack flow follows a structured path: First, an authenticated attacker with contributor privileges navigates to the Smart Slider 3 editor. Second, the attacker modifies a slide configuration, injecting a crafted payload into the 'data-href' field. An example of such a payload would be 'javascript:alert(document.cookie)' or a more complex sequence designed to inject script tags after closing the attribute context. Third, the application saves this malicious input into the database without sanitization. Finally, when any user—including administrators—views the page where the slider is embedded, the injected script is rendered directly into the HTML source. The victim's browser executes the script immediately, as the application fails to perform proper output escaping, thereby granting the attacker the ability to execute arbitrary code within the victim's browser session.\nThis vulnerability is classified as stored XSS because the malicious script is persisted in the database. The impact is significant as it facilitates the theft of sensitive session cookies, the modification of site content via unauthorized API requests, and the potential for phishing or malware distribution. The threat model assumes the attacker has sufficient privilege to access the plugin dashboard. There is no requirement for network exposure beyond the standard web access provided by the WordPress installation itself, as the exploit relies entirely on the internal processing logic of the plugin.\nThe vulnerability remains present in all versions up to and including 3.5.1.38. Remediation requires the implementation of strict server-side input validation to ensure that the 'data-href' parameter contains only valid, non-executable URI structures, as well as the implementation of context-aware output encoding to prevent the browser from interpreting user-supplied data as executable scripts."
}