The MetaSlider plugin for WordPress, which includes the Slider, Gallery, and Carousel features, has a security issue. Specifically, the ‘aria-label’ parameter in versions up to 3.98.0 does not properly filter out harmful code. This means that attackers who have Contributor-level access or higher can insert their own code into pages, which will then run when a user visits those pages.