VYPR
High severity7.1NVD Advisory· Published Mar 5, 2026· Updated Apr 22, 2026

CVE-2026-28102

CVE-2026-28102

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup UberSlider Classic uberSlider_classic allows Reflected XSS.This issue affects UberSlider Classic: from n/a through <= 2.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS in WordPress UberSlider Classic plugin versions <= 2.5 allows attackers to inject malicious scripts via a crafted link.

Vulnerability

Overview

The UberSlider Classic plugin for WordPress versions up to and including 2.5 contains a reflected cross-site scripting (XSS) vulnerability due to improper neutralization of user input during web page generation [1]. This vulnerability allows attackers to inject arbitrary HTML and JavaScript into the plugin's output.

Exploitation

Details

Successful exploitation requires user interaction, as the victim must click a malicious link, visit a specially crafted page, or submit a form [1]. The attack does not require authentication, making it accessible to any actor who can deliver a crafted URL to a user of a site running the vulnerable plugin [1].

Impact

An attacker can inject malicious scripts that may execute in the context of the victim's session. This can lead to redirects to malicious sites, display of unauthorized advertisements, or other HTML payloads that execute when visitors access the affected site [1]. The vulnerability is considered moderately dangerous and is expected to be used in mass-exploit campaigns targeting thousands of websites [1].

Mitigation

As an immediate action, users should update the plugin to a patched version if available. If an update is not yet available, applying a security rule (e.g., from Patchstack) can block attacks until an official patch is released [1]. Users unable to update should consult their hosting provider or web developer for assistance [1].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.