References https://nvd.nist.gov/vuln/detail/CVE-2025-5291 https://patchstack.com/database/wordpress/plugin/master-slider/vulnerability/wordpress-master-slider-plugin-3-9-9-authenticated-contributor-stored-cross-site-scripting-vulnerability https://github.com/advisories/GHSA-wx3j-x35p-pqp4 https://cve.imfht.com/detail/CVE-2025-5291 https://www.nsfocus.net/vulndb/122553 https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/master-slider/master-slider-responsive-touch-slider-3106-authenticated-contributor-stored-cross-site-scripting-via-ms-slider-shortcode https://access.redhat.com/security/cve/cve-2025-5291
Related VulnerabilitiesPoCCVE-2026-81199: MasterStudy LMS < 3.7.46 - Unauthenticated Student Statistics DisclosurePoCCVE-2026-8037: Progress ADC LoadMaster - Command InjectionMasterStudy LMS /wp-admin/admin-ajax.php?action=stm_lms_load_content 文件包含漏洞(CVE-2024-3136)Progress Kemp LoadMaster /accessv2 命令执行漏洞(CVE-2026-8037)PoCCVE-2026-49777: WordPress Product Slider Pro for WooCommerce < 3.5.4 - Supply Chain Backdoor RCEPaperCut NG/MF /rpc/api/rest/master/user/createInternalUser;/keepalive 权限绕过漏洞 (CVE-2023-27351)PoCCVE-2026-1405: WordPress Slider Future <= 1.0.5 - Unauthenticated Arbitrary File UploadPoCCVE-2023-28787: Quiz and Survey Master <= 8.1.4 - SQL InjectionPoCCVE-2024-13224: SlideDeck 1 Lite Content Slider - Cross-Site ScriptingPoCCVE-2024-13627: OWL Carousel Slider - Cross-Site ScriptingPoCCVE-2024-24882: Masteriyo LMS <= 1.7.2 - Unauthenticated Privilege EscalationPoCCVE-2024-33939: Masteriyo LMS <= 1.7.3 - Insecure Direct Object ReferencePoCsharepoint-masterpage-disclosure: Microsoft SharePoint - Master Page Disclosure