The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘aria-label’ parameter in all versions up to, and including, 3.98.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 109,930 live websites that are affected by CVE-2025-5337.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 109,930 live websites (100% of MetaSlider for WordPress install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 0 versions ( less than 0.1% of all versions) |
![]() | 26,199 websites |
![]() | 17,559 websites |
![]() | 10,785 websites |
![]() | 5,150 websites |
![]() | 5,001 websites |
![]() | 4,090 websites |
![]() | 3,702 websites |
![]() | 3,083 websites |
![]() | 2,629 websites |
![]() | 1,980 websites |
.com | 44,006 websites |
.de | 7,059 websites |
.org | 5,638 websites |
.jp | 4,424 websites |
.ru | 3,367 websites |
.net | 3,161 websites |
.co.uk | 2,854 websites |
.nl | 2,794 websites |
.fr | 2,627 websites |
.it | 2,621 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*******.com | ![]() | *,*** | |
*********.******.com | ![]() | *,*** | |
**********.ru | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
**************.ca | ![]() | **,*** | |
****************.com | ![]() | **,*** | |
*********************.org | ![]() | **,*** | |
*************.com | ![]() | **,*** | |
****.***.uk | ![]() | **,*** | |
**********.com | ![]() | **,*** |
FAQ