Executive brief
SliceWP, a WordPress plugin used for managing affiliate marketing programs, contains a security vulnerability that allows attackers to inject malicious scripts into the website. If an administrator or visitor views a page containing this script, the attacker could potentially hijack user sessions, redirect visitors to malicious websites, or deface the site. This issue impacts the integrity of the website and the security of its users' data.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the SliceWP plugin for WordPress due to improper neutralization of input during web page generation. The flaw allows an unauthenticated remote attacker to inject arbitrary web scripts into the database, which are later executed in the browser of a victim (typically an administrator) who views the affected page. The vulnerability has a CVSS score of 7.1, reflecting that while it requires user interaction, it can lead to a full compromise of the user's session within the application. The issue is resolved in version 1.2.7.
Affected products
- iova.Mihai SliceWP n/a through 1.2.6
Timeline
- 2026-03-12: other: Reported by Nguyen Ba Khanh
- 2026-05-06: advisory: Patchstack advisory published
- 2026-06-11: disclosed: CVE published to NVD