CVE-2026-76789: Slider Hero < 9.1.3 - Unauthenticated Stored XSS via Slider Type Change and Add-Slider Handlers
The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and does not escape a stored setting before outputting it, allowing unauthenticated users to store malicious JavaScript which will be executed in the context of an administrator viewing the Slider Hero with Video Background, Animation WordPress plugin before 9.1.3's admin area, as well as any visitor of a page embedding a slider.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue and where does the payload execute?
An unauthenticated attacker can store malicious JavaScript through the affected request handlers. The script can execute when an administrator views the plugin's admin area and when visitors view a page that embeds the affected slider.
Which installations are affected?
Slider Hero with Video Background, Animation WordPress plugin versions before 9.1.3 are affected. The issue stems from missing authorization and nonce checks on two request handlers and unescaped output of a stored setting.