CVE-2026-16537: Slick Slider < 0.5.3 - Contributor+ Stored XSS via Gallery Shortcode
Published Aug 6, 2026
·Updated
The Slick Slider WordPress plugin before 0.5.3 does not sanitize and escape a shortcode attribute value before outputting it in an HTML attribute, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute when a user views the affected post.
Affected Software
1 affected component
Slick Slider WordPress plugin "Slick Slider"<0.5.3
Event History
Aug 6, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-16537?
CVE-2026-16537 has a risk score of 40, indicating a moderate severity level.
2
How do I fix CVE-2026-16537?
To fix CVE-2026-16537, update the Slick Slider WordPress plugin to version 0.5.3 or later.
3
What type of vulnerability is CVE-2026-16537?
CVE-2026-16537 is a Stored Cross-Site Scripting (XSS) vulnerability.
4
Who is impacted by CVE-2026-16537?
Users with Contributor roles and above can exploit CVE-2026-16537 to perform attacks.
5
What does CVE-2026-16537 allow attackers to do?
CVE-2026-16537 allows attackers to execute Stored XSS attacks when a user views an affected post.