THREAT OPS › Threat News › [NVD] CVE-2026-18344 (MEDIUM 6.1) — The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in versions up to, and excluding, 1.1.53. This is due to insufficient input sanitization and output escaping in the responsive_thumbnail_image_management
[NVD] CVE-2026-18344 (MEDIUM 6.1) — The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in versions up to, and excluding, 1.1.53. This is due to insufficient input sanitization and output escaping in the responsive_thumbnail_image_management
CVE-2026-18344 CVSS: 6.1 MEDIUM Published: 2026-08-01T09:17:02.237
The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in versions up to, and excluding, 1.1.53. This is due to insufficient input sanitization and output escaping in the responsive_thumbnail_image_management() function, which echoes $_GET['id'] directly into
Indicators of compromise
- CVE-2026-18344cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18344