VYPR
High severity7.1NVD Advisory· Published Mar 5, 2026· Updated Apr 22, 2026

CVE-2026-28103

CVE-2026-28103

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup LBG Zoominoutslider lbg_zoominoutslider allows Reflected XSS.This issue affects LBG Zoominoutslider: from n/a through <= 5.4.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

LBG Zoominoutslider plugin ≤5.4.5 reflects user input without sanitization, enabling XSS via crafted requests.

Vulnerability

Overview

The LBG Zoominoutslider WordPress plugin versions up to and including 5.4.5 suffer from a reflected cross-site scripting (XSS) vulnerability caused by improper neutralization of user-supplied input during web page generation [1]. This flaw allows an attacker to inject arbitrary HTML or JavaScript code into a dynamically generated page response.

Attack

Vector and Prerequisites

Exploitation does not require authentication but does depend on user interaction. The attacker must trick a privileged user (e.g., an administrator) into clicking a crafted link, visiting a specially prepared page, or submitting a malicious form [1]. The injected script executes in the context of the victim's session and within the affected WordPress admin or site page.

Impact

Successful exploitation enables the attacker to inject malicious scripts such as redirects, advertisements, or other HTML payloads. When the victim visits the compromised page, the script can perform actions like session hijacking, defacement, or phishing within the trusted site context [1]. This type of XSS is frequently used in mass-exploit campaigns targeting thousands of websites [1].

Mitigation

Status

Users should update the plugin immediately to a patched version beyond 5.4.5. As an interim measure, Patchstack has released a mitigation rule that blocks attacks until an official patch can be safely applied [1]. Organizations unable to update should consult their hosting provider or web developer for assistance [1].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.