Executive brief
The Simple SEO Slideshow plugin for WordPress, which is used to create image galleries, contains a security flaw that allows users with contributor-level access to inject malicious scripts into pages. These scripts execute automatically when any visitor, including site administrators, views the affected page. This could lead to unauthorized actions being performed in the context of an administrator's session or the theft of sensitive information.
Technical details
The Simple SEO Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on shortcode attributes. Authenticated attackers with contributor-level permissions or higher can exploit this by injecting malicious web scripts into posts via shortcodes. Because the WordPress KSES filter does not adequately strip malicious values from shortcode attributes during the post-saving process, these payloads are persisted in the database. The scripts execute in the browser of any user who views the post, potentially allowing for session hijacking or administrative account takeover. The vulnerability affects all versions up to and including 1.2.8.
Affected products
- Simple SEO Slideshow Simple SEO Slideshow up to, and including, 1.2.8
Timeline
- 2026-06-06: disclosed
- 2026-06-06: advisory
References
- https://plugins.trac.wordpress.org/browser/simple-seo-slideshow/trunk/simpleslideshow.php
- https://plugins.trac.wordpress.org/browser/simple-seo-slideshow/trunk/simpleslideshow.php
- https://plugins.trac.wordpress.org/browser/simple-seo-slideshow/trunk/simpleslideshow.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3551425%40simple-seo-slideshow&new=3551425%40simple-seo-slideshow&sfp_email=&sfph_mail=
- https://www.wordfence.com/threat-intel/vulnerabilities/id/3b3bb703-fdff-4525-9272-7a3db58b81a0?source=cve