Executive brief
The Splide Carousel Block plugin for WordPress, which allows users to create image sliders, contains a security flaw that allows users with contributor-level access to embed malicious scripts into website pages. If an administrator or editor approves and publishes a post containing this malicious code, the script will execute in the browsers of any site visitors. This could lead to unauthorized actions being performed on behalf of visitors or the theft of sensitive session information.
Technical details
The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'url' block attribute. Authenticated attackers with contributor-level permissions or higher can exploit this by injecting arbitrary web scripts into the attribute. The vulnerability is triggered when a user visits a page where the malicious payload has been published. Because contributors cannot publish posts directly, the exploit requires an editor or administrator to approve and publish the affected post before the script can execute for general site visitors. The issue is present in all versions up to and including 1.7.1.
Affected products
- Splide Carousel Block Team Splide Carousel Block Up to and including 1.7.1
Timeline
- 2026-05-27: disclosed: CVE-2026-9022 published by Wordfence/NVD
References
- https://plugins.trac.wordpress.org/browser/splide-carousel/tags/1.7.1/build/carousel-item/index.js
- https://plugins.trac.wordpress.org/browser/splide-carousel/tags/1.7.1/build/carousel/view.js
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3537643%40splide-carousel&new=3537643%40splide-carousel&sfp_email=&sfph_mail=
- https://www.wordfence.com/threat-intel/vulnerabilities/id/268f2ae1-5360-4ec5-bcd9-dc3ab11396dc?source=cve