The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘aria-label’ parameter in all versions up to, and including, 3.98.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 57,801 live websites that are affected by CVE-2025-5337.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 57,801 live websites (45% of MetaSlider for WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 128 versions ( 93% of all versions) |
| 10,666 websites | |
| 9,870 websites | |
| 5,601 websites | |
| 3,017 websites | |
| 2,926 websites | |
| 2,359 websites | |
| 2,119 websites | |
| 1,724 websites | |
| 1,514 websites | |
| 1,376 websites |
| .com | 21,977 websites |
| .de | 3,627 websites |
| .jp | 2,807 websites |
| .ru | 2,500 websites |
| .org | 2,364 websites |
| .it | 1,631 websites |
| .net | 1,600 websites |
| .co.uk | 1,343 websites |
| .nl | 1,315 websites |
| .co.jp | 1,310 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.com | *,*** | ||
| **********.ru | **,*** | ||
| *******.com | **,*** | ||
| **************.ca | **,*** | ||
| **********.com | **,*** | ||
| *********************.pl | **,*** | ||
| *********.**.jp | **,*** | ||
| ******.*******.**.jp | **,*** | ||
| ******.*****.edu | **,*** | ||
| ********.**.jp | **,*** |
FAQ