What the vulnerability does
01Description
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Image Slider by NextCode plugin <= 1.1.2 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Image Slider by NextCode plugin <= 1.1.2 at WordPress.
Explanation of Vulnerability in Simple Terms
The Image Slider by NextCode plugin for WordPress versions up to 1.1.2 is vulnerable to cross-site request forgery (CSRF). An attacker can craft a malicious webpage that, when visited by a logged-in site administrator, performs unwanted actions on the site without their knowledge. This can result in unauthorized changes to slider settings or data.
What an attacker can do
Trick a site admin into visiting a malicious page that modifies slider settings or deletes slider data without their consent.
Potential impact on your site
Attackers can modify or delete image sliders and their settings if they trick your admin into visiting a malicious link.
Conditions required to exploit
A logged-in WordPress administrator must visit an attacker-controlled webpage while the vulnerable plugin is active.
Key dates
External resources
Related vulnerabilities