Junglewise Threat Intelligence

CVE-2019-25743: Soliloquy Lite persistent XSS in post title

CVE-2019-25743 · Severity: medium · CVSS 6.4 · Published 2026-06-04

Executive brief

Soliloquy Lite, a popular WordPress plugin used to create image and video sliders, contains a security flaw that allows users with posting privileges to inject malicious scripts into slider titles. These scripts are saved on the website and execute when other users, such as administrators, preview or view the affected slider. This could lead to unauthorized actions being performed in the context of the victim's session, potentially compromising the website's management interface.

Technical details

A persistent cross-site scripting (XSS) vulnerability exists in Soliloquy Lite 2.5.6 due to improper neutralization of input in the post title field. An authenticated attacker with permissions to create or edit sliders can submit a POST request to the 'post.php' endpoint containing a malicious JavaScript payload in the 'post_title' parameter. Because the plugin fails to sanitize this input before storage, the payload is executed in the browser of any user who subsequently previews or views the slider in the WordPress administrative interface. This can be used to hijack administrative sessions or perform unauthorized configuration changes.

Affected products

  • Soliloquy Soliloquy Lite 2.5.6

Timeline

  • 2019-06-13: disclosed: Vulnerability discovered by researcher
  • 2019-10-17: other: Exploit published on Exploit-DB
  • 2026-06-04: advisory: NVD publication date

References