CVE-2026-16537
Received Received - Intake

Stored XSS in Slick Slider WordPress Plugin

Vulnerability report for CVE-2026-16537, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: WPScan

Description

The Slick Slider WordPress plugin before 0.5.3 does not sanitize and escape a shortcode attribute value before outputting it in an HTML attribute, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute when a user views the affected post.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-06
AI Q&A
2026-08-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Slick Slider WordPress plugin before version 0.5.3 has a stored Cross-Site Scripting (XSS) vulnerability. It fails to sanitize and escape a shortcode attribute value before outputting it in an HTML attribute. This allows users with Contributor role or higher to inject malicious scripts that execute when others view the affected post.

Detection Guidance

Check the installed version of the Slick Slider WordPress plugin. If it is below 0.5.3, the system is vulnerable. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files for version details.

Impact Analysis

Attackers with Contributor access or higher can inject malicious scripts into posts. When users view these posts, the scripts execute, potentially stealing session cookies, redirecting to malicious sites, or performing actions on behalf of the user.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating GDPR's data protection requirements or HIPAA's security rules. Organizations may face compliance penalties if user data is compromised through such attacks.

Mitigation Strategies

Update the Slick Slider plugin to version 0.5.3 or later immediately. If updating is not possible, consider disabling the plugin temporarily until an update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16537. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart