Junglewise Threat Intelligence

CVE-2026-16260: Post Grid, Slider & Carousel Ultimate stored XSS in Header Title

CVE-2026-16260 · Severity: medium · CVSS 6.8 · Published 2026-08-22

Executive brief

The Post Grid, Slider & Carousel Ultimate WordPress plugin is used to display custom post types in grid and carousel layouts on WordPress sites. A vulnerability allows users with Contributor role or higher to inject malicious JavaScript into the plugin's Header Title field, which executes in the administrator's browser when they edit the affected item, potentially compromising site security or admin accounts.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw in the plugin's custom post type settings. The plugin fails to sanitise and escape the Header Title field value before outputting it in an HTML attribute on the admin edit screen (CWE-79). An attacker with Contributor role or above can inject JavaScript through the Header Title field (e.g., x" autofocus onfocus="alert(document.domain)), which persists in the database as stored XSS. When an administrator opens the affected item for editing, the unescaped payload executes in their browser session with admin privileges. The vulnerability was fixed in version 1.8.1. The same unescaped output pattern also affects the Total Posts and Image Width fields.

Affected products

  • Post Grid, Slider & Carousel Ultimate Post Grid, Slider & Carousel Ultimate before 1.8.1

Timeline

  • 2026-08-20: disclosed
  • 2026-08-20: patched: Fixed in version 1.8.1

References