CVE-2025-1062: Slider, Gallery, Carousel by MetaSlider < 3.95.0 - Editor+ Stored XSS
The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1062?
CVE-2025-1062 has a high severity rating due to its potential for allowing stored cross-site scripting attacks by privileged users.
How do I fix CVE-2025-1062?
To fix CVE-2025-1062, update the MetaSlider plugin to version 3.95.0 or later.
Who is affected by CVE-2025-1062?
CVE-2025-1062 affects users of the MetaSlider, Gallery, and Carousel plugin for WordPress prior to version 3.95.0.
What types of attacks can CVE-2025-1062 allow?
CVE-2025-1062 can allow high privilege users to perform stored cross-site scripting (XSS) attacks.
What settings are vulnerable in CVE-2025-1062?
CVE-2025-1062 involves unsanitized and unescaped settings in the MetaSlider plugin.