CVE-2025-1203: Slider, Gallery, Carousel by MetaSlider < 3.95.0 - Editor+ Stored XSS
The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise and escape some of its settings, which could allow high privilege users such as editor to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1203?
CVE-2025-1203 has a moderate severity rating as it allows high privilege users to perform Stored Cross-Site Scripting attacks.
How do I fix CVE-2025-1203?
To fix CVE-2025-1203, update the MetaSlider plugin to version 3.95.0 or later.
Who is affected by CVE-2025-1203?
CVE-2025-1203 affects users of the MetaSlider plugin for WordPress prior to version 3.95.0, especially those with editor or higher privileges.
What types of attacks can CVE-2025-1203 facilitate?
CVE-2025-1203 can facilitate Stored Cross-Site Scripting attacks due to improper sanitization and escaping of settings.
Which version of MetaSlider addresses CVE-2025-1203?
MetaSlider version 3.95.0 and later address the vulnerabilities outlined in CVE-2025-1203.