ZeroHour

CVE-2026-82224

niche

Unauthenticated Cross-Site Scripting in SliceWP WordPress plugin (≤ 1.2.10)

CVSS 3.1
7.1 high
EPSS
<1%p4
Published
()
Modified
AI analysis

CVE-2026-82224 is an unauthenticated cross-site scripting (XSS) flaw in the SliceWP affiliate plugin for WordPress, affecting all versions up to and including 1.2.10. Because no authentication or privileges are required, any remote attacker can craft a malicious request or link that injects script content which then executes in the browser of a site visitor or administrator when triggered. Per the CVSS vector, successful exploitation requires some user interaction (e.g., clicking a crafted link or loading a page) and can impact content beyond the immediate injection point, allowing the attacker to steal cookies or session data, redirect users, or perform actions in the WordPress admin under the victim's session. Any WordPress site running SliceWP 1.2.10 or older is affected. There is currently no known public proof-of-concept, no CISA KEV listing, and a low EPSS score (0.1% over 30 days), indicating exploitation is not known to be occurring.

What to do: Update SliceWP to the latest patched release (any version above 1.2.10). If immediate update is not possible, temporarily deactivate the plugin and/or apply WAF rules to block unauthenticated requests containing script payloads, and check the site (pages, posts, stored plugin settings) for signs of injected JavaScript.

Affected
SliceWP (WordPress affiliate plugin)<= 1.2.10
Estimated exposure
nicheroughly a few thousand sites (SliceWP is a niche affiliate plugin with low-thousands of active installs on WordPress.org) — SliceWP is a low-adoption WordPress.org affiliate-marketing plugin whose public directory listing shows on the order of only a few thousand active installations.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 1.2.10 versions.

Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.