What is CVE-2026-16537?
CVE-2026-16537: The Slick Slider WordPress plugin before version 0.5.3 fails to sanitize and escape a shortcode attribute value before outputting it in an HTML attribute. This allows users with the Contributor role and above to perform Stored Cross-Site Scripting attacks, executing malicious scripts when other users view the affected post. Immediate update to version 0.5.3 or later is required.
Azərbaycanca: CVE-2026-16537: "Slick Slider" WordPress plagininin 0.5.3-dən əvvəlki versiyalarında qısayol atributu düzgün təmizlənmədiyi üçün Stored XSS zəifliyi mövcuddur. Bu, Contributor və yuxarı roluna malik istifadəçilərə, təsirə məruz qalan səhifəni ziyarət edən digər istifadəçilərin brauzerində zərərli skript icra etməyə imkan verir. Plagini dərhal 0.5.3 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Slick Slider plugin are affected by CVE-2026-16537?
This vulnerability affects the Slick Slider WordPress plugin before version 0.5.3.
What minimum user role is required to exploit CVE-2026-16537?
The attacker must have the Contributor role or above.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.