CVE-2026-76789Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and does not escape a stored setting before outputting it, allowing unauthenticated users to store malicious JavaScript which will be executed in the context of an administrator viewing the Slider Hero with Video Background, Animation WordPress plugin before 9.1.3's admin area, as well as any visitor of a page embedding a slider.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-22: 2Technical Details · 2026-08-22: 208-22
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-76789 The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and does n… https://www.cve.org/CVERecord?id=CVE-2026-76789

    Post summary

    The Slider Hero plugin (before version 9.1.3) has missing authorisation and nonce checks on two request handlers, exposing it to potential unauthorized exploitation (CVE‑2026‑76789).

    00000681
    58.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-76789 Stored XSS in Slider Hero WordPress Plugin Before 9.1.3 Allows Administrator Account Takeover https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-76789

    Post summary

    A stored XSS vulnerability in Slider Hero WordPress plugin (versions before 9.1.3) allows attackers to compromise administrator accounts.

    00000110
    4.1K followersView on X

Explore more