CVE-2025-5337

Slider, Gallery, and Carousel by MetaSlider <= 3.98.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via aria-label Parameter

The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘aria-label’ parameter in all versions up to, and including, 3.98.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 57,801 live websites that are affected by CVE-2025-5337.

Run a Free Instant Scan




Affected Software

Product  MetaSlider for WordPress
Category Wordpress Plugins
Vulnerable Domains57,801 live websites (45% of MetaSlider for WordPress install base)
Vulnerable Versions
  • from 0 through 3.98
Vulnerable Versions Count128 versions ( 93% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jun 14, 2025
  • Updated - Apr 8, 2026

Credits

  • Asaf Mozes (finder)

Website Distribution by Country

Number of websites using CVE-2025-5337
United States10,666 websites



Japan9,870 websites
Germany5,601 websites
Russia3,017 websites
France2,926 websites
Italy2,359 websites
GB2,119 websites
Poland1,724 websites
Netherlands1,514 websites
Vietnam1,376 websites

Website Distribution by TLD

Number of websites using CVE-2025-5337
.com21,977 websites
.de3,627 websites
.jp2,807 websites
.ru2,500 websites
.org2,364 websites
.it1,631 websites
.net1,600 websites
.co.uk1,343 websites
.nl1,315 websites
.co.jp1,310 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-5337

Top websites that are affected by CVE-2025-5337. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com United States*,***
**********.ru Russia**,***
*******.com Japan**,***
**************.ca Canada**,***
**********.com United States**,***
*********************.pl Poland**,***
*********.**.jp United States**,***
******.*******.**.jp Japan**,***
******.*****.edu United States**,***
********.**.jp Japan**,***
See full domain list

FAQ

CVE-2025-5337 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in MetaSlider for WordPress
A total of 57,801 websites have been identified as vulnerable to CVE-2025-5337, based on global website indexing conducted by WebTechSurvey.
The MetaSlider for WordPress is affected by the CVE-2025-5337 vulnerability.
MetaSlider for WordPress versions up to and including 3.98 are vulnerable to CVE-2025-5337.