๐Ÿ” CVE Alert

CVE-2026-14844

UNKNOWN 0.0

Master Slider <= 3.11.2 - Contributor+ Stored XSS via ms_slider Shortcode Attributes

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Master Slider WordPress plugin through 3.11.2 does not sanitise and escape some of its shortcode attributes before outputting them in an inline script context, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute when the affected post is viewed. No fixed version is available. Until one ships, restrict the Contributor role to trusted users, or deactivate the Master Slider WordPress plugin through 3.11.2. Site owners who need to keep it active can block the ms_slider shortcode for roles below Editor, for example with a shortcode-restriction Master Slider WordPress plugin through 3.11.2, which prevents the attack without removing the Master Slider WordPress plugin through 3.11.2.

Vendor unknown
Product master slider
Published Sep 20, 2026
Stay Ahead of the Next One

Get instant alerts for unknown master slider

Be the first to know when new unknown vulnerabilities affecting unknown master slider are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Master Slider
0 โ‰ค 3.11.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/06a5409c-3070-417f-98cb-0ca8ddbfe14c/

Credits

WEI HSIANG WANG WPScan