CVE-2025-5291

Published
View on NVD ↗
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's masterslider_pb and ms_slide shortcodes in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

<p><a href="https://wordpress.org/plugins/depicter" title="Depicter" rel="ugc">Meet <strong>Depicter</strong></a>, the next generation of Master slider, the ultimate tool for creating engaging WordPress slider, carousel, hero section, popup, post slider, product slider, WooCommerce slider, testimonial slider, gallery slider.<br /> <a href="https://wordpress.org/plugins/depicter" title="Get started with Depicter" rel="ugc">Start using Depicter, it&#8217;s free!</a></p> <h4>Overview</h4> <p>Master Slider is a free SEO friendly, responsive image and video slider that truly works on all major devices, and it has super smooth hardware accelerated transitions. It supports touch navigation with pure swipe gesture that you have never experienced before.</p> <p><a href="http://avt.li/mswftem" title="Live demos of Master Slider free version" rel="nofollow ugc">Demos</a> | <a href="http://avt.li/mswfea" title="All features" rel="nofollow ugc">Features</a> | <a href="http://avt.li/mswfdoc" title="Master Slider documentation" rel="nofollow ugc">Documentation</a> | <a href="http://avt.li/msfvids" title="Watch all video tutorials" rel="nofollow ugc">Videos</a> | <a href="https://wordpress.org/support/plugin/master-slider" title="Free support" rel="ugc">Support</a></p> <span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/nyjpGEHwOn8?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span> <p>With our 8 Starter Samples, creating slideshows has never been so fast and enjoyable!</p> <blockquote> <p>Looking for a perfect Free WordPress theme optimized for both Master Slider and Elementor? <a href="http://avt.li/msphpp" title="Phlox theme - Free Minimal and Responsive WordPress Theme" rel="nofollow ugc">Get Phlox theme</a></p> </blockquote> <p>Master Slider is built using WordPress best practices both on the front and the back end. This results in an efficient, robust and intuitive plugin. It works with any theme, including WordPress Default Themes.</p> <h4>Features</h4> <p>• The Most SEO Friendly Slider Plugin in Market!<br /> • Easy to Use Interface<br /> • Simply Create Fully Responsive and Device Optimized Sliders with 8 starter samples<br /> • Use Sliders Cross-browser and Works Well on All Popular Browsers! (Tested IE8+ and other modern browsers)<br /> • Superlative Lightweight Outputs in Compare with Other Plugins<br /> • HTML5 Valid and Clean Markups<br /> • Touch Swipe Navigation<br /> • Manage Slideshows with Autoplay Timing Options!<br /> • 24h Support with Expert Agents (check out our rates on WordPress)<br /> • Drag and Drop Slider Creation<br /> • Extremely User Friendly Admin Panel<br /> • CSS3 Transitions with jQuery Fallback<br /> • Hardware Accelerated CSS3 3D Transforms<br /> • Optimized for Any Screen Sizes and Touch Devices<br /> • Smart Loading Assets<br /> • 6+ Interactive Slide Transitions<br /> • Smart auto crop<br /> • Loop and linear sliding<br /> • Shuffle Ordering Slides Option<br /> • Auto-height Slider<br /> • Vertical and Horizontal Direction Navigation<br /> • Fully Customizable Thumbnail and Tabs<br /> • Vertical and Horizontal Bullets<br /> • Mouse Wheel Navigation<br /> • Customizable Arrows<br /> • Exclusive Widget and Shortcodes<br /> • Scroll Handle Slide Indicator<br /> • Smart Memory Management<br /> • 6 Modern and Unique Skins<br /> • Timer-bar and Circle Timer UI Controls<br /> • Custom User Roles and Capabilities<br /> • 5 Image Positioning Options (fill, fit, tile,&#8230;)<br /> • Advanced Import And Export Tool<br /> • Built-in Cache Boosting<br /> • Translate Ready<br /> • Multisite Compatible<br /> • Extensive Developer API<br /> * <a href="https://masterslider.com/wordpress/free/?mslf" rel="nofollow ugc">Full List of Features</a></p> <h4>Compatible Browsers</h4> <ul> <li>IE8+</li> <li>Firefox</li> <li>Safari</li> <li>Opera</li> <li>Chrome</li> <li>iOS browser</li> <li>Android browser</li> </ul> <h4>Master Slider Pro Features</h4> <ul> <li>Full-width, Full-screen and Boxed Layout</li> <li>Post Slider &#8211; with Advanced Filtering Tool (Any Post-type)</li> <li>WooCommerce Product Slider &#8211; With Advanced Filtering Tool</li> <li>Flickr Slider &#8211; Make Slider Dynamically From Flickr Photosets or User Latest Photos</li> <li>Facebook Slider &#8211; Make Image Gallery Dynamically From Facebook Public Images</li> <li>HD Video Backgrounds for Slides</li> <li>Embedding YouTube and Vimeo Videos</li> <li>Animated Layers</li> <li>4 Different Layer Types (Text, Image, Button and Video)</li> <li>Huge Verity of Layer Transitions</li> <li>Transition In and Out Available for Each Layer</li> <li>Hotspots and Tooltips over Slides</li> <li>Deep-linking</li> <li>Parallax Effect while Scrolling</li> <li>Layers Parallax Effect while Swiping</li> <li>Layers Parallax Effect while Moving Mouse over Slide</li> <li>Boxed with Visible Nearby Slides</li> <li>Auto Height and Auto Fill Layout</li> <li>Binding Special Actions to Layers (Go to slide, scroll down, play, pause, ..)</li> <li>Custom Pattern and Color Overlay</li> <li>Auto Resizing and Aligning Layers while Resizing</li> <li>Option to Linking Slides, Layers and Hotspots</li> <li>30+ Ready to Use Sample Sliders (One Click Import)</li> <li>Nice Looking and Easy to Use Layout</li> <li>WYSIWYG Drag &amp; Drop Editor</li> <li>Easy to Use Timeline animation tool</li> <li>Visual Style Editor</li> <li>Visual Transition Effect Editor</li> <li>Visual Button Editor</li> <li>Easy Aligning Layers over Stage</li> <li>Snapping Option on Drag &amp; Drop Layers</li> <li>9 Different Positioning Origin Points for Each Layer</li> <li>Realtime Animation Preview</li> <li>Moving Layers by Arrow Keys</li> <li>Using WordPress Native Text Editor</li> <li>Using Google Fonts (600+ Fonts)</li> <li><a href="https://masterslider.com/wordpress/pro/?mslf" rel="nofollow ugc">Full List of Pro Features</a></li> </ul> <p>Upgrade to <a href="https://masterslider.com/purchase/?mslf" rel="nofollow ugc">Pro Version</a></p> <h4>Demo for PRO Version</h4> <ul> <li><a href="http://avt.li/mswptem" rel="nofollow ugc">Master Slider Demo Sliders</a></li> <li><a href="http://avt.li/mswpfea" rel="nofollow ugc">Master Slider Features</a></li> <li><a href="http://avt.li/mswpdoc" rel="nofollow ugc">Master Slider Manual</a></li> </ul> <h4>Documentations</h4> <p>If you have any question about working with &#8220;Master Slider&#8221;, you can take a look at <a href="https://masterslider.com/doc/wp/free/" rel="nofollow ugc">online documentations</a></p> <h4>Translation</h4> <p>French. Special thanks to <a href="http://www.thomasgrimaud.fr" rel="nofollow ugc">Thomas</a><br /> Brazilian Portuguese. Special thanks to <a href="http://www.themeforest.net/user/WebPress-CodeLayer" rel="nofollow ugc">WebPress</a><br /> Serbian. Special thanks to <a href="http://www.webhostinghub.com" rel="nofollow ugc">Borisa Djuraskovic</a></p> <p>You can start translating Master Slider by our <a href="http://translate.averta.net/projects/masterslider/free-version" rel="nofollow ugc">online translation service</a>.</p>
WordPress Plugin DirectoryWordPress Plugin Directory
3.19M