CVE-2025-58025: WordPress Master Slider Plugin <= 3.11.0 - Cross Site Scripting (XSS) Vulnerability
Published Sep 22, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in averta Master Slider master-slider allows Stored XSS.This issue affects Master Slider: from n/a through <= 3.11.0.
Affected Software
3 affected components
averta Master Slider<=3.11.0
WordPress Master Slider plugin<=3.11.0
averta Master Slider Wordpress<=3.11.0
Event History
Sep 22, 2025
CVE Published
via MITRE·06:23 PM
Data Sourced
via MITRE·06:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Oct 28, 58279
Event
via MITRE·03:27 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-58025?
CVE-2025-58025 is a medium severity vulnerability that allows for Stored Cross-site Scripting (XSS).
2
How do I fix CVE-2025-58025?
To fix CVE-2025-58025, upgrade Averta Master Slider to version 3.11.1 or higher immediately.
3
What is the impact of CVE-2025-58025?
CVE-2025-58025 can lead to unauthorized access to user data and potentially allow attackers to execute malicious scripts in a victim's browser.
4
Which versions of Master Slider are affected by CVE-2025-58025?
CVE-2025-58025 affects all versions of Master Slider up to and including 3.11.0.
5
Does CVE-2025-58025 affect the WordPress Master Slider Plugin?
Yes, CVE-2025-58025 also affects the WordPress Master Slider Plugin up to version 3.11.0.