CVE-2026-16260: CWE-79 Cross-Site Scripting (XSS) in Post Grid, Slider & Carousel Ultimate
The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before outputting it in an HTML attribute on the admin edit screen, allowing users with the Contributor role and above to inject JavaScript that executes in the session of any administrator who opens the affected item.
AI Analysis
Technical Summary
The Post Grid, Slider & Carousel Ultimate WordPress plugin before version 1.8.1 contains a CWE-79 Cross-Site Scripting vulnerability. Specifically, one of its custom post type settings is not sanitized or escaped before being output in an HTML attribute on the admin edit screen. This enables users with Contributor or higher privileges to inject arbitrary JavaScript, which executes in the session of administrators who open the affected post item. This vulnerability can lead to session hijacking or other malicious actions performed with administrator privileges.
Potential Impact
An attacker with Contributor or higher privileges can inject JavaScript code that executes in the administrator's browser session when they open the affected post item. This can lead to unauthorized actions performed with administrator privileges, including potential session hijacking or other malicious activities within the WordPress admin interface.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict Contributor role users from accessing the affected plugin features or monitor for suspicious activity. Avoid opening affected items in the admin interface by administrators unless necessary and ensure strict role management.
CVE-2026-16260: CWE-79 Cross-Site Scripting (XSS) in Post Grid, Slider & Carousel Ultimate
Description
The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before outputting it in an HTML attribute on the admin edit screen, allowing users with the Contributor role and above to inject JavaScript that executes in the session of any administrator who opens the affected item.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Post Grid, Slider & Carousel Ultimate WordPress plugin before version 1.8.1 contains a CWE-79 Cross-Site Scripting vulnerability. Specifically, one of its custom post type settings is not sanitized or escaped before being output in an HTML attribute on the admin edit screen. This enables users with Contributor or higher privileges to inject arbitrary JavaScript, which executes in the session of administrators who open the affected post item. This vulnerability can lead to session hijacking or other malicious actions performed with administrator privileges.
Potential Impact
An attacker with Contributor or higher privileges can inject JavaScript code that executes in the administrator's browser session when they open the affected post item. This can lead to unauthorized actions performed with administrator privileges, including potential session hijacking or other malicious activities within the WordPress admin interface.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict Contributor role users from accessing the affected plugin features or monitor for suspicious activity. Avoid opening affected items in the admin interface by administrators unless necessary and ensure strict role management.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-20T08:30:12.390Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a893cc5acd9273b49a6fe98
Added to database: 08/22/2026, 06:08:05 UTC
Last enriched: 08/22/2026, 06:22:56 UTC
Last updated: 08/23/2026, 00:21:17 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.