CVE-2025-5337: Slider, Gallery, and Carousel by MetaSlider <= 3.98.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via aria-label Parameter
The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘aria-label’ parameter in all versions up to, and including, 3.98.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5337?
CVE-2025-5337 is classified as a high severity vulnerability due to its potential for Stored Cross-Site Scripting.
How do I fix CVE-2025-5337?
To fix CVE-2025-5337, update the Slider, Gallery, and Carousel by MetaSlider plugin to the latest version beyond 3.98.0.
What systems are affected by CVE-2025-5337?
CVE-2025-5337 affects all versions of the Slider, Gallery, and Carousel by MetaSlider plugin for WordPress up to and including version 3.98.0.
What are the exploitation impacts of CVE-2025-5337?
Exploitation of CVE-2025-5337 could allow attackers to execute arbitrary JavaScript in the context of a user's session.
Is user authentication required to exploit CVE-2025-5337?
No, CVE-2025-5337 may be exploited by unauthenticated users due to the nature of the stored Cross-Site Scripting vulnerability.