WPIntell

Source evidence

3.11.2 – Unauthenticated Stored Cross-Site Scripting

Master Slider – Responsive Touch Slider · support · 2026-06-24T11:07:00+00:00

complaintsentiment
highseverity
1.0relevance
3replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

6 / 31 rows with source links

19.4% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

25 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
kovokswp unresolved
The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.11.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/master-slider/master-slider-responsive-touch-slider-3112-unauthenticated-stored-cross-site-scripting I am afraid they won’t reply here, like they didn’t reply here to any support topic in over a year, not even on tickets about previous security issues. Last time I posted the issue in the support threads for their Depicter plugin, where they actively provide support. Will do that again now. It looks like they only keep this plugin alive to promote their new depicter plugin. Thanks John-Pierre, hopefully they will do something about it. Thanks for pursuing this issue Have a lovely day, Warm Regards, Marijke @jpnl Your topic about a topic which you intentionally opened in the wrong support forum has been removed. Please do not repeat that. If this plugin is not supported, and that’s fine as developers are not compelled to support anything, then your option is to remove the plugin and find a replacement.

Comments

3 shown
John-Pierre Cornelissen 2026-06-25T10:47:00+00:00

I am afraid they won’t reply here, like they didn’t reply here to any support topic in over a year, not even on tickets about previous security issues. Last time I posted the issue in the support threads for their Depicter plugin, where they actively provide support. Will do that again now. It looks like they only keep this plugin alive to promote their new depicter plugin.

kovokswp 2026-06-29T10:01:00+00:00

Thanks John-Pierre, hopefully they will do something about it. Thanks for pursuing this issue Have a lovely day, Warm Regards, Marijke

Support Moderator 2026-06-29T10:15:00+00:00

@jpnl Your topic about a topic which you intentionally opened in the wrong support forum has been removed. Please do not repeat that. If this plugin is not supported, and that’s fine as developers are not compelled to support anything, then your option is to remove the plugin and find a replacement.