SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-16260

MEDIUM · CVSS 6.8 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Post Grid, Slider & Carousel Ultimate WordPress plugin prior to version 1.8.1 is vulnerable due to insufficient sanitization of a custom post type setting, enabling users with Contributor roles and higher to inject malicious JavaScript into HTML attributes. This can lead to session hijacking of administrators who view the compromised item, posing a significant security risk. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-16260
Severity
MEDIUM
CVSS
6.8
EPSS
0.29%
WordPress Java

Original NVD Description

The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before outputting it in an HTML attribute on the admin edit screen, allowing users with the Contributor role and above to inject JavaScript that executes in the session of any administrator who opens the affected item.