What the vulnerability does
01Description
Slider by Soliloquy 2.6.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the title parameter. Attackers can add JavaScript payloads in the title field when creating or editing sliders, which executes in the browsers of users viewing the slider on both administrative and frontend pages.
Explanation of Vulnerability in Simple Terms
02Summary
Slider by Soliloquy contains a cross-site scripting (XSS) vulnerability in version 2.6.2. An attacker with low-level site access can inject malicious scripts that execute in other users' browsers when they interact with the slider. The vulnerability requires user interaction to trigger. Update to a version newer than 2.6.2.
What an attacker can do
03Attacker Capabilities
Inject malicious scripts that run in other users' browsers when they view or interact with the slider.
Potential impact on your site
04Site Impact
Site visitors' sessions could be compromised or malicious content injected into pages displaying the slider.
Conditions required to exploit
05Prerequisites
Attacker needs low-level site access (e.g., contributor or subscriber role) and the victim must view the affected slider.
Key dates
06Disclosure timeline
May 10, 2026
CVE published
July 28, 2026
Record updated