CVE-2026-32494: WordPress Image Slider by Ays plugin <= 2.7.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Image Slider by Ays ays-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Slider by Ays: from n/a through <= 2.7.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32494?
CVE-2026-32494 has a moderate severity level due to its potential for Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2026-32494?
To fix CVE-2026-32494, update the Ays Image Slider by Ays plugin to version 2.7.2 or later.
What are the potential impacts of CVE-2026-32494?
The potential impacts of CVE-2026-32494 include unauthorized access to sensitive information and the ability to execute malicious scripts in the context of the user’s browser.
Who is affected by CVE-2026-32494?
Users of Ays Image Slider by Ays plugin versions 2.7.1 and below are affected by CVE-2026-32494.
What type of vulnerability is CVE-2026-32494?
CVE-2026-32494 is a Cross-Site Scripting (XSS) vulnerability caused by improper input handling during web page generation.