CVE-2025-5337

Slider, Gallery, and Carousel by MetaSlider <= 3.98.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via aria-label Parameter

The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘aria-label’ parameter in all versions up to, and including, 3.98.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 109,930 live websites that are affected by CVE-2025-5337.

Run a Free Instant Scan




Affected Software

Product  MetaSlider for WordPress
Category Wordpress Plugins
Vulnerable Domains109,930 live websites (100% of MetaSlider for WordPress install base)
Vulnerable Versions
  • from 0 through 3.98
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jun 14, 2025
  • Updated - Jun 17, 2025

Credits

  • Asaf Mozes (finder)

Website Distribution by Country

Number of websites using CVE-2025-5337
United States26,199 websites



Japan17,559 websites
Germany10,785 websites
GB5,150 websites
France5,001 websites
Russia4,090 websites
Italy3,702 websites
Netherlands3,083 websites
Poland2,629 websites
Canada1,980 websites

Website Distribution by TLD

Number of websites using CVE-2025-5337
.com44,006 websites
.de7,059 websites
.org5,638 websites
.jp4,424 websites
.ru3,367 websites
.net3,161 websites
.co.uk2,854 websites
.nl2,794 websites
.fr2,627 websites
.it2,621 websites

Websites affected by CVE-2025-5337

Top websites that are affected by CVE-2025-5337. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com United States*,***
*********.******.com United States*,***
**********.ru Russia**,***
*******.com Japan**,***
**************.ca Canada**,***
****************.com United States**,***
*********************.org United States**,***
*************.com United States**,***
****.***.uk United States**,***
**********.com United States**,***
See full domain list

FAQ

CVE-2025-5337 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in MetaSlider for WordPress
A total of 109,930 websites have been identified as vulnerable to CVE-2025-5337, based on global website indexing conducted by WebTechSurvey.
The MetaSlider for WordPress is affected by the CVE-2025-5337 vulnerability.
MetaSlider for WordPress versions up to and including 3.98 are vulnerable to CVE-2025-5337.