
株式会社mgn@mgn_jpn
🚨 Smart Slider 3 に脆弱性(深刻度 中) 80万サイト以上が利用 / CVSS 6.4 修正版 3.5.1.39 が公開済み https://shindan.m-g-n.me/alerts/cve-2026-14876/
00100439
315 followersView on X
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-href' parameter in all versions up to, and including, 3.5.1.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

🚨 Smart Slider 3 に脆弱性(深刻度 中) 80万サイト以上が利用 / CVSS 6.4 修正版 3.5.1.39 が公開済み https://shindan.m-g-n.me/alerts/cve-2026-14876/