CVE-2026-42711: WordPress Slider by 10Web plugin <= 1.2.63 - Cross Site Scripting (XSS) vulnerability
Published Oct 10, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in Slider by 10Web <= 1.2.63 versions.
Affected Software
1 affected component
10web Slider by 10Web<=1.2.63
Event History
Oct 10, 2026
CVE Published
via MITRE·07:35 PM
Data Sourced
via MITRE·07:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The issue is unauthenticated, so an attacker does not need an account or prior privileges. Exploitation still requires user interaction, as indicated by the UI:R vector.
2
What security impact could successful exploitation have?
The vulnerability is rated high with a 7.1 CVSS score. Its vector indicates low impact to confidentiality, integrity, and availability, with scope changed.
3
Which plugin versions are affected?
Slider by 10Web versions up to and including 1.2.63 are affected.