Junglewise Threat Intelligence

CVE-2026-56014: Averta Master Slider XSS in WordPress plugin

CVE-2026-56014 · Severity: high · CVSS 7.1 · Published 2026-06-25

Executive brief

Master Slider is a popular WordPress plugin used to create responsive image and video slideshows. A security vulnerability allows unauthenticated attackers to inject malicious scripts into the website, which could lead to unauthorized redirects, theft of user session cookies, or the display of fraudulent content to visitors. This occurs when a victim, such as a site administrator, interacts with a specially crafted link or page.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Averta Master Slider plugin for WordPress through version 3.11.2. The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link or visiting a crafted URL. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized actions on the WordPress site. As of the advisory date, no official patch has been released.

Affected products

  • Averta Master Slider <= 3.11.2

Timeline

  • 2026-05-30: other: Vulnerability reported by researcher João Pedro S Alcântara (Kinorth)
  • 2026-06-19: advisory: Initial advisory published by Patchstack
  • 2026-06-25: disclosed: CVE published to NVD

References

Related threats