The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and does not escape a stored setting before outputting it, allowing unauthenticated users to store malicious JavaScript which will be executed in the context of an administrator viewing the Slider Hero with Video Background, Animation WordPress plugin before 9.1.3's admin area, as well as any visitor of a page embedding a slider.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-22 06:16
Updated : 2026-08-26 16:30
NVD link : CVE-2026-76789
Mitre link : CVE-2026-76789
CVE.ORG link : CVE-2026-76789
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
