CVE-2026-14844 Details
Description
The Master Slider WordPress plugin through 3.11.2 does not sanitise and escape some of its shortcode attributes before outputting them in an inline script context, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute when the affected post is viewed. No fixed version is available. Until one ships, restrict the Contributor role to trusted users, or deactivate the Master Slider WordPress plugin through 3.11.2. Site owners who need to keep it active can block the ms_slider shortcode for roles below Editor, for example with a shortcode-restriction Master Slider WordPress plugin through 3.11.2, which prevents the attack without removing the Master Slider WordPress plugin through 3.11.2.
A stored cross-site scripting vulnerability has been identified in the Master Slider WordPress plugin, affecting versions through 3.11.2. The issue arises because the plugin fails to properly sanitize and escape certain shortcode attributes before rendering them in an inline script context. This flaw enables users with Contributor roles and above to execute scripts that are triggered when the affected post is viewed.
No official fix is available for this vulnerability. Users can deactivate the Master Slider WordPress plugin or restrict the Contributor role to trusted users. If the plugin must remain active, site owners can block the 'ms_slider' shortcode for roles below Editor using a shortcode-restriction plugin.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 20, 2026CISA-ADP
Assessed Sep 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/06a5409c-3070-417f-98cb-0ca8ddbfe14c/ | [email protected] | AdvisoryPartial ContentRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Master Slider | <= 3.11.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 20, 2026 | CVE Modified | CISA-ADP |
| Sep 20, 2026 | New CVE Received | [email protected] |
Volerion