Junglewise Threat Intelligence

CVE-2026-14844: Master Slider WordPress plugin stored cross-site scripting via shortcode attributes

CVE-2026-14844 · Severity: medium · CVSS 6.8 · Published 2026-09-20

Executive brief

The Master Slider WordPress plugin through version 3.11.2 fails to properly sanitize shortcode attributes before inserting them into JavaScript, allowing authenticated users with the Contributor role or higher to inject malicious code. When a post containing the affected shortcode is viewed, the injected code executes in visitors' browsers, potentially leading to account takeover, credential theft, or malware distribution. No patch is currently available.

Technical details

The plugin does not sanitize and escape shortcode attributes before outputting them in an inline script context, allowing Stored XSS via the ms_slider shortcode. The vulnerability requires authentication (Contributor role or above) and execution occurs when a post is viewed. An attacker with the required role can inject arbitrary JavaScript that persists in the database and executes for all site visitors viewing the affected post.

Affected products

  • Master Slider Master Slider through 3.11.2

Timeline

  • 2026-09-18: disclosed
  • 2026-09-20: advisory

References