Social Slider Feed < 2.2.9 - Admin+ Stored XSS via Widgets
Description
Social Slider Feed WordPress plugin before 2.2.9 allows admin-level stored XSS via unsanitized settings.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Social Slider Feed WordPress plugin before 2.2.9 allows admin-level stored XSS via unsanitized settings.
Vulnerability
The Social Slider Feed WordPress plugin versions before 2.2.9 fail to sanitize and escape some of its settings. This allows administrators to inject arbitrary web scripts into widget settings, which are stored and later executed in the context of other users' sessions. The vulnerability is present in all plugin versions prior to 2.2.9 [1].
Exploitation
An attacker must have administrator-level access to the WordPress site, including in multisite configurations where the "unfiltered_html" capability is normally disallowed. The attacker can inject malicious JavaScript into unsanitized plugin settings fields, such as those used in widgets. The injected script is then stored and executed whenever the affected widget is rendered for any user (including lower-privileged users or visitors) [1].
Impact
Successful exploitation results in stored cross-site scripting (XSS). An attacker can execute arbitrary JavaScript in the browser of any user viewing the affected widget. This can lead to session hijacking, redirection to malicious sites, or other client-side attacks. The attacker does not need the "unfiltered_html" capability, making the vulnerability especially dangerous in multisite environments [1].
Mitigation
The vulnerability is fixed in version 2.2.9 of the Social Slider Feed plugin. Administrators should update to this version immediately. No workarounds are documented in the available references [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/1619dc4b-4e5e-4b82-820b-3c4e732db3ad/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.