CVE-2021-47922

MEDIUM

WordPress Plugin Slider by Soliloquy 2.6.2 Stored XSS

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-47922. PoCs published by Abdurrahman Erkan.

AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in WordPress Plugin Slider by Soliloquy 2.6.2. The attacker injects malicious JavaScript into the 'title' field of a post, which executes when the post is viewed by authenticated or unauthenticated users.

Description

Slider by Soliloquy 2.6.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the title parameter. Attackers can add JavaScript payloads in the title field when creating or editing sliders, which executes in the browsers of users viewing the slider on both administrative and frontend pages.

Exploits (1)

exploitdb WORKING POC
by Abdurrahman Erkan · textwebappsphp
https://www.exploit-db.com/exploits/50563

This exploit demonstrates a stored XSS vulnerability in WordPress Plugin Slider by Soliloquy 2.6.2. The attacker injects malicious JavaScript into the 'title' field of a post, which executes when the post is viewed by authenticated or unauthenticated users.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: WordPress Plugin Slider by Soliloquy 2.6.2
Auth required
Prerequisites: WordPress installation with Soliloquy plugin 2.6.2 · Authenticated access to create/edit posts
devstral-2 · analyzed May 10, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-50563
https://www.exploit-db.com/exploits/50563
Product product
Official Product Homepage
https://soliloquywp.com/
Product product
Product Reference
https://wordpress.org/plugins/soliloquy-lite/
Third Party Advisory third-party-advisory
VulnCheck Advisory: WordPress Plugin Slider by Soliloquy 2.6.2 Stored XSS
https://www.vulncheck.com/advisories/wordpress-plugin-slider-by-soliloquy-stored-xss

Scores

CVSS v3 6.4
EPSS 0.0024
EPSS Percentile 15.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
Soliloquywp/Slider by Soliloquy 2.6.2
Published May 10, 2026
Tracked Since May 10, 2026