CVE-2026-76789: CWE-79 Cross-Site Scripting (XSS) in Slider Hero with Video Background, Animation
Description
The Slider Hero with Video Background, Animation WordPress plugin before version 9.1.3 contains a Cross-Site Scripting (XSS) vulnerability. This flaw arises from missing authorization and nonce checks on two request handlers and failure to escape stored settings before output. As a result, unauthenticated users can inject malicious JavaScript that executes in the context of administrators viewing the plugin's admin area and visitors viewing pages embedding the affected slider.
CVSS v3.1
Score 8.8high
Affected software
Slider Hero with Video Background, Animation
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-76789 is a high-severity Cross-Site Scripting (CWE-79) vulnerability in the Slider Hero with Video Background, Animation WordPress plugin versions prior to 9.1.3. The vulnerability is due to lack of authorization and nonce verification on two request handlers, combined with improper escaping of stored settings before output. This allows unauthenticated attackers to inject and store malicious JavaScript code, which executes when an administrator accesses the plugin's admin interface or when any visitor views a page containing the vulnerable slider. The CVSS v3.1 base score is 8.8, indicating a high impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation enables unauthenticated attackers to execute arbitrary JavaScript in the context of administrators and site visitors. This can lead to full compromise of administrator accounts, site defacement, theft of sensitive information, and potential further attacks on users. The vulnerability affects both the admin area and public-facing pages embedding the slider.
Mitigation Recommendations
A fixed version 9.1.3 or later should be applied to remediate this vulnerability. Since no explicit patch links or vendor advisory are provided, users should verify availability of the official update from the plugin vendor or WordPress plugin repository. Until patched, restrict access to the plugin's admin area and avoid embedding the vulnerable slider on public pages if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-08-19T17:55:37.640Z
- State
- PUBLISHED
Threat ID: 6a893cc5acd9273b49a6fea6
Added to database: 08/22/2026, 06:08:05 UTC
Last enriched: 09/10/2026, 15:18:45 UTC
Last updated: 10/06/2026, 18:48:25 UTC
Views: 75
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.