The Master Slider plugin 3.2.7 and 3.5.1 for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings value on Callback.
| Software | From | Fixed in |
|---|---|---|
| averta / master_slider | 3.5.1 | 3.5.1.x |
| averta / master_slider | 3.2.7 | 3.2.7.x |