CVE-2026-16260

The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before outputting it in an HTML attribute on the admin edit screen, allowing users with the Contributor role and above to inject JavaScript that executes in the session of any administrator who opens the affected item.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-22 06:16

Updated : 2026-08-26 16:30


NVD link : CVE-2026-16260

Mitre link : CVE-2026-16260

CVE.ORG link : CVE-2026-16260


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')