The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'delay' Post Meta Setting in all versions up to, and including, 3.111.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The ml-slider custom post type is registered without custom capability restrictions and the ml-slider_settings meta key is unprotected, allowing Author-level users to set the malicious delay value via XML-RPC custom_fields when creating an ml-slider post.
We have discovered 159,765 live websites that are affected by CVE-2026-18400.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 159,765 live websites (99% of MetaSlider for WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 143 versions ( 99% of all versions) |
| 43,217 websites | |
| 22,384 websites | |
| 18,587 websites | |
| 7,767 websites | |
| 7,372 websites | |
| 5,104 websites | |
| 4,979 websites | |
| 4,085 websites | |
| 3,385 websites | |
| 3,190 websites |
| .com | 63,345 websites |
| .de | 13,106 websites |
| .org | 10,513 websites |
| .jp | 5,581 websites |
| .nl | 4,680 websites |
| .net | 4,359 websites |
| .co.uk | 3,966 websites |
| .fr | 3,868 websites |
| .it | 3,529 websites |
| .ru | 3,369 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.com | *,*** | ||
| ***********************.com | *,*** | ||
| *********.******.com | *,*** | ||
| ***************.com | **,*** | ||
| *************.org | **,*** | ||
| **********.ru | **,*** | ||
| *******.com | **,*** | ||
| **************.de | **,*** | ||
| *******.com | **,*** | ||
| ******.org | **,*** |
FAQ