Executive brief
The Master Slider WordPress plugin through version 3.11.2 fails to properly sanitize shortcode attributes before inserting them into JavaScript, allowing authenticated users with the Contributor role or higher to inject malicious code. When a post containing the affected shortcode is viewed, the injected code executes in visitors' browsers, potentially leading to account takeover, credential theft, or malware distribution. No patch is currently available.
Technical details
The plugin does not sanitize and escape shortcode attributes before outputting them in an inline script context, allowing Stored XSS via the ms_slider shortcode. The vulnerability requires authentication (Contributor role or above) and execution occurs when a post is viewed. An attacker with the required role can inject arbitrary JavaScript that persists in the database and executes for all site visitors viewing the affected post.
Affected products
- Master Slider Master Slider through 3.11.2
Timeline
- 2026-09-18: disclosed
- 2026-09-20: advisory