CVE-2024-6026 – The Slider by 10Web WordPress plugin before 1.2.5

CVE ID : CVE-2024-6026

Published : July 11, 2024, 6:15 a.m. | 1 hour, 4 minutes ago

Description : The Slider by 10Web WordPress plugin before 1.2.56 does not sanitise and escape some of its Slide options, which could allow authenticated users with access to the Sliders (by default Administrator, however this can be changed via the Slider by 10Web WordPress plugin before 1.2.56’s options) and the ability to add images (Editor+) to perform Stored Cross-Site Scripting attacks

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…CVE ID : CVE-2024-6026

Published : July 11, 2024, 6:15 a.m. | 1 hour, 4 minutes ago

Description : The Slider by 10Web WordPress plugin before 1.2.56 does not sanitise and escape some of its Slide options, which could allow authenticated users with access to the Sliders (by default Administrator, however this can be changed via the Slider by 10Web WordPress plugin before 1.2.56’s options) and the ability to add images (Editor+) to perform Stored Cross-Site Scripting attacks

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…