CVE-2026-28099: WordPress UberSlider Ultra plugin <= 2.3 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup UberSlider Ultra uberSliderultra allows Reflected XSS.This issue affects UberSlider Ultra: from n/a through <= 2.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28099?
CVE-2026-28099 is a high-severity vulnerability due to its ability to allow reflected Cross Site Scripting (XSS).
How do I fix CVE-2026-28099?
To fix CVE-2026-28099, update the UberSlider Ultra plugin to version 2.4 or later.
What is the impact of CVE-2026-28099 on my website?
The impact of CVE-2026-28099 can result in unauthorized execution of scripts on your site, leading to potential data theft or user impersonation.
Is CVE-2026-28099 easy to exploit?
Yes, CVE-2026-28099 can be easily exploited by sending specially crafted requests to the affected plugin, bypassing security measures.
Who is affected by CVE-2026-28099?
CVE-2026-28099 affects all users of the UberSlider Ultra plugin version 2.3 and below.