CVE-2026-97253: WordPress LayerSlider plugin <= 8.4.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kreatura LayerSlider allows Reflected XSS.
This issue affects LayerSlider: from n/a through 8.4.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress LayerSlider pluginto a version that resolves this vulnerability.Fixed in 8.4.1
Event History
Frequently Asked Questions
What must an attacker do to exploit this issue?
An attacker must cause a user to interact with a crafted request or page, as indicated by the required user interaction in the CVSS vector. No attacker privileges are required.
What is the potential impact if exploitation succeeds?
Successful exploitation can affect confidentiality, integrity, and availability at a low impact level. The CVSS vector also indicates that the vulnerable component’s security scope can be crossed.
Which LayerSlider versions are affected?
LayerSlider versions through 8.4.0 are affected. The available information does not identify a fixed version.