CVE-2023-1473

CVE-2023-1473: Responsive WordPress Slideshows 3.29.0 - Reflected XSS

Vendor Unknown
Product Slider, Gallery, and Carousel by MetaSlider
Published April 17, 2023
Last update February 6, 2025

CVSS base score

What the vulnerability does

01Description

The Slider, Gallery, and Carousel by MetaSlider WordPress plugin 3.29.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Key dates

02Disclosure timeline

April 17, 2023 CVE published
February 6, 2025 Record updated