Sceawere
Vulnerability Detail
CVE-2026-97253UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
LayerSlider Reflected XSS Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- Kreatura
- Product
- LayerSlider
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kreatura LayerSlider allows Reflected XSS. This issue affects LayerSlider: from n/a through 8.4.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-09-30T13:17:37.257Z",
"pubdate": "2026-09-30T13:17:37.257Z",
"executiveSummary": "The Kreatura LayerSlider plugin is susceptible to a Reflected Cross-Site Scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation.\nThis vulnerability exists within versions ranging from n/a through 8.4.0.\nAn unauthenticated attacker can exploit this flaw by crafting malicious links that, when clicked by a victim, execute arbitrary JavaScript in the context of the user's browser session.\nThe successful exploitation of this vulnerability can lead to session hijacking, unauthorized actions performed on behalf of the user, and the exfiltration of sensitive information.\nBecause this is a reflected attack, it typically requires the victim to interact with a specifically crafted link, such as one distributed via email or social engineering tactics.\nGiven the nature of XSS, the risk is categorized as significant for administrators or users with high-privilege sessions within the WordPress environment where LayerSlider is installed.",
"technicalDetails": "The root cause of this vulnerability is the failure of the Kreatura LayerSlider plugin to adequately sanitize or encode input parameters before reflecting them back to the user's browser in an HTTP response. This reflects a breakdown in the secure coding practices required to prevent injection attacks during the construction of dynamic web pages.\nThe vulnerability is classified under CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').\nIn a typical attack flow, the attacker identifies a vulnerable parameter within the plugin that is reflected in the HTML output without proper validation. The attacker constructs a malicious URL containing a JavaScript payload—for example, <script>alert('XSS')</script>—encoded within the vulnerable parameter. When an authenticated user, such as an administrator, is induced to click this link, the web server processes the request and includes the malicious payload directly into the rendered HTML page returned to the victim's browser.\nBecause the payload is delivered as part of the legitimate response from the trusted web application, the victim's browser executes the script under the origin of the vulnerable site. This bypasses the Same-Origin Policy (SOP) constraints, allowing the injected script to access document objects, session cookies, and local storage.\nTechnical exploitation does not necessarily require direct access to the plugin's internal settings by the attacker; rather, it exploits the plugin's public-facing interfaces that process input. The vulnerability is present in versions 8.4.0 and all prior versions. The exploitation vector is network-based, utilizing standard HTTP/HTTPS protocols.\nThe post-exploitation impact includes the potential for full account takeover if session cookies are accessed, the ability to modify the visual content of the page (defacement), or the injection of additional malicious scripts to conduct further reconnaissance or administrative abuse within the WordPress dashboard.\nSuccessful execution depends on the application's failure to implement proper Content Security Policy (CSP) headers or context-aware output encoding (e.g., using WordPress-specific functions like esc_html() or esc_js()) on the reflected parameters."
}