The Logo Slider WordPress plugin before 4.9.0 does not validate and escape some of its slider options before outputting them back in the dashboard, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
History

Fri, 02 Jan 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Logo Slider WordPress plugin before 4.9.0 does not validate and escape some of its slider options before outputting them back in the dashboard, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Title Logo Slider < 4.9.0 - Contributor+ Stored XSS
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-01-02T06:00:11.428Z

Reserved: 2025-11-13T21:28:12.187Z

Link: CVE-2025-13153

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-02T06:15:53.423

Modified: 2026-01-02T06:15:53.423

Link: CVE-2025-13153

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.