VYPR
High severity7.1NVD Advisory· Published Mar 5, 2026· Updated Apr 22, 2026

CVE-2026-28109

CVE-2026-28109

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup LambertGroup - AllInOne - Content Slider all-in-one-contentSlider allows Reflected XSS.This issue affects LambertGroup - AllInOne - Content Slider: from n/a through <= 3.8.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A reflected XSS vulnerability in LambertGroup AllInOne Content Slider WordPress plugin allows attackers to inject malicious scripts, enabling mass exploitation campaigns.

The LambertGroup AllInOne Content Slider plugin for WordPress versions up to and including 3.8 suffers from a reflected cross-site scripting vulnerability due to improper neutralization of user input during web page generation. This allows an attacker to craft a URL that, when visited, injects arbitrary HTML and JavaScript into the site [1].

Exploitation requires user interaction, typically a privileged user clicking a malicious link or visiting a crafted page. Despite this requirement, the vulnerability is considered moderately dangerous and is expected to be exploited in mass campaigns targeting thousands of websites. No authentication is needed for the attack vector, and the injected script executes in the context of the victim's browser [1].

Successful exploitation enables the attacker to inject malicious scripts such as redirects, advertisements, or other HTML payloads. These scripts execute when other users visit the affected site, potentially leading to further attacks or compromise of site visitors [1].

As of publication, no official patch has been released for this vulnerability. Patchstack has provided a virtual patch or mitigation rule to block attacks until an update becomes available. Users are advised to apply the mitigation rule or update the plugin once a patched version is released [1].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.