CVE-2026-76789
Received Received - Intake

Stored Cross-Site Scripting in Slider Hero with Video Background WordPress Plugin

Vulnerability report for CVE-2026-76789, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-22

Last updated on: 2026-08-22

Assigner: WPScan

Description

The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and does not escape a stored setting before outputting it, allowing unauthenticated users to store malicious JavaScript which will be executed in the context of an administrator viewing the Slider Hero with Video Background, Animation WordPress plugin before 9.1.3's admin area, as well as any visitor of a page embedding a slider.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-22
Last Modified
2026-08-22
Generated
2026-08-22
AI Q&A
2026-08-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
slider_hero slider_hero to 9.1.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unauthenticated stored cross-site scripting (XSS) flaw in the Slider Hero with Video Background, Animation WordPress plugin before version 9.1.3. It occurs because the plugin lacks authorization and nonce checks on two request handlers and fails to escape a stored setting before outputting it. Attackers can inject malicious JavaScript that executes when an administrator views the plugin's admin area or when visitors access a page with an embedded slider.

Detection Guidance

Check if the Slider Hero WordPress plugin version is below 9.1.3. Inspect admin pages and embedded sliders for unusual JavaScript execution or unexpected content. Review server logs for unauthorized POST requests to plugin handlers.

Impact Analysis

This vulnerability allows unauthenticated attackers to inject malicious JavaScript into the plugin's settings. When an administrator views the plugin's admin area or visitors access a page with an embedded slider, the injected script executes. This could lead to unauthorized actions, data theft, or further compromise of the WordPress site.

Compliance Impact

This vulnerability could lead to data breaches or unauthorized access, which may violate GDPR (data protection) and HIPAA (health information privacy) requirements. Non-compliance risks include fines, legal action, and reputational damage due to compromised user data or administrative control.

Mitigation Strategies

Update the Slider Hero plugin to version 9.1.3 or later immediately. Remove any suspicious JavaScript snippets from plugin settings. Restrict admin access to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76789. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart