CVE-2025-5291: Master Slider <= 3.10.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via masterslider_pb and ms_slide Shortcodes
The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mastersliderpb and msslide shortcodes in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5291?
CVE-2025-5291 is classified as a medium severity vulnerability due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2025-5291?
To fix CVE-2025-5291, update the Master Slider – Responsive Touch Slider plugin to version 3.10.9 or later.
What versions are affected by CVE-2025-5291?
CVE-2025-5291 affects all versions of the Master Slider – Responsive Touch Slider plugin up to and including version 3.10.8.
What type of vulnerability is CVE-2025-5291?
CVE-2025-5291 is a stored cross-site scripting (XSS) vulnerability primarily affecting user-supplied data.
Who is the vendor for CVE-2025-5291?
The vendor for CVE-2025-5291 is Master Slider, the developer of the Master Slider – Responsive Touch Slider plugin.