Slider, Gallery, and Carousel by MetaSlider <= 3.98.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via aria-label Parameter
Description
Stored XSS in MetaSlider WordPress plugin via 'aria-label' parameter allows authenticated attackers with Contributor+ access to inject arbitrary scripts.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stored XSS in MetaSlider WordPress plugin via 'aria-label' parameter allows authenticated attackers with Contributor+ access to inject arbitrary scripts.
Vulnerability
The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the aria-label parameter in all versions up to and including 3.98.0. The vulnerability stems from insufficient input sanitization and output escaping, allowing malicious input to be stored and later rendered unsafely in the browser [1].
Exploitation
An authenticated attacker with at least Contributor-level access can inject arbitrary web scripts by supplying a crafted aria-label value when creating or editing a slide. The injected script is stored in the database and executed whenever a user accesses a page containing the affected slider [1].
Impact
Successful exploitation enables the attacker to execute arbitrary JavaScript in the context of the victim's browser. This can lead to session hijacking, defacement, redirection to malicious sites, or theft of sensitive information such as cookies and authentication tokens [1].
Mitigation
The vulnerability is fixed in version 3.109.0 of the plugin, as indicated by the plugin's update history [1]. Users should update to this version or later immediately. No workaround is available; updating is the only reliable mitigation.
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Range: <=3.98.0
- Range: 0
Patches
1r3309932Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- plugins.trac.wordpress.org/browser/ml-slider/tags/3.98.0/assets/metaslider/script.jsmitre
- plugins.trac.wordpress.org/changeset/3309932/ml-slider/tags/3.99.0/assets/metaslider/script.jsmitre
- wordpress.org/plugins/ml-slider/mitre
- www.wordfence.com/threat-intel/vulnerabilities/id/0e6492e5-a506-4d77-96d2-08f700b6ee76mitre
News mentions
0No linked articles in our index yet.