What the vulnerability does
01Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Solwin Infotech Responsive WordPress Slider – Avartan Slider Lite plugin <= 1.5.3 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Solwin Infotech Responsive WordPress Slider – Avartan Slider Lite plugin <= 1.5.3 versions.
Explanation of Vulnerability in Simple Terms
The Avartan Slider Lite WordPress plugin through version 1.5.3 contains a stored cross-site scripting (XSS) vulnerability. An attacker can inject malicious JavaScript into slider content that executes in the browsers of site visitors. The vulnerability requires user interaction—a victim must visit a page containing the malicious slider. This can lead to session hijacking, credential theft, or malware distribution.
What an attacker can do
Inject JavaScript that runs in visitors' browsers when they view pages with the slider.
Potential impact on your site
Visitors' sessions and credentials can be compromised; malware or phishing content can be injected into your site.
Conditions required to exploit
No authentication required. A victim must visit a page containing the malicious slider content.
Key dates
External resources
Related vulnerabilities