{"api_version":"1","generated_at":"2026-08-22T11:38:34+00:00","cve":"CVE-2026-16260","urls":{"html":"https://cve.report/CVE-2026-16260","api":"https://cve.report/api/cve/CVE-2026-16260.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-16260","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-16260"},"summary":{"title":"Post Grid, Slider & Carousel Ultimate < 1.8.1 - Contributor+ Stored XSS via Header Title Field","description":"The Post Grid, Slider & Carousel Ultimate  WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before outputting it in an HTML attribute on the admin edit screen, allowing users with the Contributor role and above to inject JavaScript that executes in the session of any administrator who opens the affected item.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-08-22 06:16:14","updated_at":"2026-08-22 06:16:14"},"problem_types":["CWE-79 Cross-Site Scripting (XSS)"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/87c95831-d1b4-42b2-8fc7-6cba60fca400/","name":"https://wpscan.com/vulnerability/87c95831-d1b4-42b2-8fc7-6cba60fca400/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-16260","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16260","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"Post Grid, Slider & Carousel Ultimate","version":"affected 1.8.1 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Yaswanth Reddy Sunkara","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Post Grid, Slider & Carousel Ultimate","vendor":"Unknown","versions":[{"lessThan":"1.8.1","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Yaswanth Reddy Sunkara"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The Post Grid, Slider & Carousel Ultimate  WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before outputting it in an HTML attribute on the admin edit screen, allowing users with the Contributor role and above to inject JavaScript that executes in the session of any administrator who opens the affected item."}],"problemTypes":[{"descriptions":[{"description":"CWE-79 Cross-Site Scripting (XSS)","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-22T06:00:15.962Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/87c95831-d1b4-42b2-8fc7-6cba60fca400/"}],"source":{"discovery":"EXTERNAL"},"title":"Post Grid, Slider & Carousel Ultimate < 1.8.1 - Contributor+ Stored XSS via Header Title Field","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-16260","datePublished":"2026-08-22T06:00:15.962Z","dateReserved":"2026-07-20T08:30:12.390Z","dateUpdated":"2026-08-22T06:00:15.962Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-22 06:16:14","lastModifiedDate":"2026-08-22 06:16:14","problem_types":["CWE-79 Cross-Site Scripting (XSS)"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"16260","Ordinal":"1","Title":"Post Grid, Slider & Carousel Ultimate < 1.8.1 - Contributor+ Sto","CVE":"CVE-2026-16260","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"16260","Ordinal":"1","NoteData":"The Post Grid, Slider & Carousel Ultimate  WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before outputting it in an HTML attribute on the admin edit screen, allowing users with the Contributor role and above to inject JavaScript that executes in the session of any administrator who opens the affected item.","Type":"Description","Title":"Post Grid, Slider & Carousel Ultimate < 1.8.1 - Contributor+ Sto"}]}}}