CVE-2026-82224
nicheUnauthenticated Cross-Site Scripting in SliceWP WordPress plugin (≤ 1.2.10)
CVE-2026-82224 is an unauthenticated cross-site scripting (XSS) flaw in the SliceWP affiliate plugin for WordPress, affecting all versions up to and including 1.2.10. Because no authentication or privileges are required, any remote attacker can craft a malicious request or link that injects script content which then executes in the browser of a site visitor or administrator when triggered. Per the CVSS vector, successful exploitation requires some user interaction (e.g., clicking a crafted link or loading a page) and can impact content beyond the immediate injection point, allowing the attacker to steal cookies or session data, redirect users, or perform actions in the WordPress admin under the victim's session. Any WordPress site running SliceWP 1.2.10 or older is affected. There is currently no known public proof-of-concept, no CISA KEV listing, and a low EPSS score (0.1% over 30 days), indicating exploitation is not known to be occurring.
What to do: Update SliceWP to the latest patched release (any version above 1.2.10). If immediate update is not possible, temporarily deactivate the plugin and/or apply WAF rules to block unauthenticated requests containing script payloads, and check the site (pages, posts, stored plugin settings) for signs of injected JavaScript.
| SliceWP (WordPress affiliate plugin) | <= 1.2.10 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 1.2.10 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.