CVE-2026-28109: WordPress LambertGroup - AllInOne - Content Slider plugin <= 3.8 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup LambertGroup - AllInOne - Content Slider all-in-one-contentSlider allows Reflected XSS.This issue affects LambertGroup - AllInOne - Content Slider: from n/a through <= 3.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28109?
CVE-2026-28109 is considered a high severity vulnerability due to its potential for XSS attacks.
How do I fix CVE-2026-28109?
To fix CVE-2026-28109, update the LambertGroup AllInOne - Content Slider plugin to version 3.9 or later.
What type of vulnerability is CVE-2026-28109?
CVE-2026-28109 is a reflected Cross Site Scripting (XSS) vulnerability.
Can CVE-2026-28109 affect my website?
Yes, if you are using LambertGroup's AllInOne - Content Slider plugin version 3.8 or earlier, your website is at risk.
What are the potential impacts of CVE-2026-28109?
The impacts of CVE-2026-28109 include unauthorized access to sensitive data and potential website defacement.