VYPR
Medium severity6.4NVD Advisory· Published Jun 6, 2026

CVE-2026-8900

CVE-2026-8900

Description

Stored XSS in Simple SEO Slideshow plugin for WordPress allows authenticated users to inject scripts via shortcode attributes, impacting site visitors.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in Simple SEO Slideshow plugin for WordPress allows authenticated users to inject scripts via shortcode attributes, impacting site visitors.

Vulnerability

The Simple SEO Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via shortcode attributes in all versions up to and including 1.2.8. This vulnerability exists due to insufficient input sanitization and output escaping, specifically within the handling of shortcode attribute values by WordPress KSES before post save.

Exploitation

An authenticated attacker with at least contributor-level access can inject arbitrary web scripts into pages by exploiting the insufficient sanitization of shortcode attribute values. The malicious scripts are persisted when the post is saved and will execute when any user, including administrators, views the compromised page.

Impact

Successful exploitation allows an attacker to execute arbitrary web scripts in the context of a victim's browser. This can lead to session hijacking, defacement, or redirection to malicious sites, impacting any user who views the injected page, regardless of their privilege level.

Mitigation

Versions of the Simple SEO Slideshow plugin up to and including 1.2.8 are affected. A patched version has not yet been publicly disclosed in the available references. Users are advised to disable or remove the plugin until a secure version is released.

AI Insight generated on Jun 6, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.