Junglewise Threat Intelligence

CVE-2026-48968: Averta Master Slider DOM-based XSS

CVE-2026-48968 · Severity: medium · CVSS 6.5 · Published 2026-05-27

Executive brief

Averta Master Slider, a popular WordPress plugin used for creating responsive image and content sliders, contains a security vulnerability that could allow an attacker to inject malicious scripts into a website. To exploit this, an attacker needs basic 'Contributor' level access and must trick a site administrator or visitor into clicking a malicious link or visiting a specific page. If successful, this could lead to unauthorized actions being performed in the victim's browser, such as redirecting users to malicious sites or stealing session information.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Averta Master Slider plugin for WordPress due to improper neutralization of user-supplied input during web page generation. The flaw is present in versions up to and including 3.10.8. An attacker with 'Contributor' level privileges can inject arbitrary JavaScript that executes in the context of a victim's browser when they interact with a specially crafted page or link (User Interaction required). This is classified as CWE-79 and carries a CVSS 3.1 base score of 6.5. The issue has been addressed in version 3.10.9.

Affected products

  • Averta Master Slider <= 3.10.8

Timeline

  • 2025-05-28: other: Reported by Peter Thaleikis
  • 2026-05-27: patched: Version 3.10.9 released
  • 2026-05-27: advisory: Published by Patchstack and NVD

References

Related threats