What the vulnerability does
01Description
Cross-Site Scripting (XSS) vulnerability in Muneeb's WP Slider Plugin <= 1.4.5 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N
What the vulnerability does
Cross-Site Scripting (XSS) vulnerability in Muneeb's WP Slider Plugin <= 1.4.5 at WordPress.
Explanation of Vulnerability in Simple Terms
The WP Slider Plugin through version 1.4.5 contains a stored cross-site scripting (XSS) vulnerability in its slider configuration. An authenticated administrator can inject malicious JavaScript that executes in the browsers of other site users viewing the slider. The vulnerability affects the plugin's data handling and does not require user interaction to trigger.
What an attacker can do
Inject malicious JavaScript that runs in visitors' browsers when they view the affected slider.
Potential impact on your site
An admin account compromise could inject malware or steal visitor data through the slider component.
Conditions required to exploit
Attacker must have administrator-level access to the WordPress site.
Key dates
External resources
Related vulnerabilities