CVE-2026-16260: Post Grid, Slider & Carousel Ultimate < 1.8.1 - Contributor+ Stored XSS via Header Title Field
The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before outputting it in an HTML attribute on the admin edit screen, allowing users with the Contributor role and above to inject JavaScript that executes in the session of any administrator who opens the affected item.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue, and who is at risk from the resulting script execution?
Any authenticated user with the Contributor role or higher can inject the malicious value. The JavaScript executes in the session of an administrator who opens the affected item in the admin edit screen.
What action is required for exploitation to succeed?
An attacker must be able to set the affected custom post type Header Title field, and an administrator must subsequently open that affected item on the admin edit screen.
Which versions are affected?
Versions of Post Grid, Slider & Carousel Ultimate before 1.8.1 are affected.