Junglewise Threat Intelligence

CVE-2026-39507: Social Slider Feed Cross-Site Scripting in WordPress plugin

CVE-2026-39507 · Severity: high · CVSS 7.1 · Published 2026-06-15

Executive brief

The Social Slider Feed plugin for WordPress, which displays social media feeds on websites, contains a security flaw that allows attackers to inject malicious scripts. If a site administrator or visitor interacts with a specially crafted link or page, the attacker could potentially hijack user sessions, redirect visitors to malicious websites, or deface the site. This vulnerability can be exploited without needing a password, making it a significant risk for site reputation and user safety.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Social Slider Feed plugin for WordPress (versions <= 2.3.2) due to improper neutralization of input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary web scripts or HTML. Exploitation requires user interaction, typically involving a privileged user clicking a malicious link or visiting a crafted page. Successful exploitation can lead to session hijacking, unauthorized actions in the context of the victim's browser, or delivery of malicious payloads to other site visitors. The issue is resolved in version 2.3.3.

Affected products

  • Social Slider Feed Social Slider Feed <= 2.3.2

Timeline

  • 2026-02-06: other: Reported by Nguyen Ba Khanh
  • 2026-04-16: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date

References