CVE-2026-16260
Received Received - Intake

Stored XSS in Post Grid Slider & Carousel Ultimate WordPress Plugin

Vulnerability report for CVE-2026-16260, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-22

Last updated on: 2026-08-22

Assigner: WPScan

Description

The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before outputting it in an HTML attribute on the admin edit screen, allowing users with the Contributor role and above to inject JavaScript that executes in the session of any administrator who opens the affected item.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-22
Last Modified
2026-08-22
Generated
2026-08-22
AI Q&A
2026-08-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpbeaverbuilder post_grid_slider_carousel_ultimate to 1.8.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in the WordPress plugin 'Post Grid, Slider & Carousel Ultimate' versions before 1.8.1. Users with the Contributor role or higher can inject malicious JavaScript via the Header Title Field in custom post type settings. The injected script executes when an administrator views the affected item, potentially compromising their session.

Detection Guidance

Check if the WordPress plugin 'Post Grid, Slider & Carousel Ultimate' is installed and its version is below 1.8.1. Log in as a user with the Contributor role or higher and inspect custom post type settings for unsanitized input in the Header Title Field. Look for unexpected JavaScript code in HTML attributes on admin edit screens.

Impact Analysis

If exploited, this vulnerability allows attackers to inject JavaScript that runs in the browser of administrators viewing the affected item. This could lead to session hijacking, unauthorized actions on the site, or theft of sensitive data like admin credentials.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate GDPR's data protection requirements if personal data is compromised. For HIPAA, it could expose protected health information if exploited in healthcare-related WordPress environments.

Mitigation Strategies

Update the 'Post Grid, Slider & Carousel Ultimate' plugin to version 1.8.1 or later immediately. If updating is not possible, consider disabling the plugin temporarily until an update is applied. Review user roles and permissions to ensure only trusted users have Contributor access or higher.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16260. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart