CVE-2026-18400

Slider, Gallery, and Carousel by MetaSlider <= 3.111.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'delay' Post Meta Setting

The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'delay' Post Meta Setting in all versions up to, and including, 3.111.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The ml-slider custom post type is registered without custom capability restrictions and the ml-slider_settings meta key is unprotected, allowing Author-level users to set the malicious delay value via XML-RPC custom_fields when creating an ml-slider post.


We have discovered 159,765 live websites that are affected by CVE-2026-18400.

Run a Free Instant Scan




Affected Software

Product  MetaSlider for WordPress
Category Wordpress Plugins
Vulnerable Domains159,765 live websites (99% of MetaSlider for WordPress install base)
Vulnerable Versions
  • from 0 through 3.111
Vulnerable Versions Count143 versions ( 99% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 6, 2026
  • Updated - Aug 6, 2026

Credits

  • haofanjiukunle (finder)

Website Distribution by Country

Number of websites using CVE-2026-18400
United States43,217 websites



Japan22,384 websites
Germany18,587 websites
France7,767 websites
GB7,372 websites
Netherlands5,104 websites
Italy4,979 websites
Russia4,085 websites
Canada3,385 websites
Poland3,190 websites

Website Distribution by TLD

Number of websites using CVE-2026-18400
.com63,345 websites
.de13,106 websites
.org10,513 websites
.jp5,581 websites
.nl4,680 websites
.net4,359 websites
.co.uk3,966 websites
.fr3,868 websites
.it3,529 websites
.ru3,369 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-18400

Top websites that are affected by CVE-2026-18400. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com United States*,***
***********************.com United States*,***
*********.******.com United States*,***
***************.com United States**,***
*************.org United States**,***
**********.ru Russia**,***
*******.com Japan**,***
**************.de Germany**,***
*******.com GB**,***
******.org United States**,***
See full domain list

FAQ

CVE-2026-18400 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in MetaSlider for WordPress
A total of 159,765 websites have been identified as vulnerable to CVE-2026-18400, based on global website indexing conducted by WebTechSurvey.
The MetaSlider for WordPress is affected by the CVE-2026-18400 vulnerability.
MetaSlider for WordPress versions up to and including 3.111 are vulnerable to CVE-2026-18400.

References