CVE-2026-76789

The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and does not escape a stored setting before outputting it, allowing unauthenticated users to store malicious JavaScript which will be executed in the context of an administrator viewing the Slider Hero with Video Background, Animation WordPress plugin before 9.1.3's admin area, as well as any visitor of a page embedding a slider.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-22 06:16

Updated : 2026-08-26 16:30


NVD link : CVE-2026-76789

Mitre link : CVE-2026-76789

CVE.ORG link : CVE-2026-76789


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')