What the vulnerability does
01Description
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Vsourz Digital Responsive Slick Slider WordPress allows Code Injection.This issue affects Responsive Slick Slider WordPress: from n/a through 1.4.
Explanation of Vulnerability in Simple Terms
02Summary
The Responsive Slick Slider WordPress plugin through version 1.4 contains a stored cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts into the plugin's settings that execute in the browsers of site administrators and visitors. This allows theft of session tokens, defacement, or malware distribution without requiring authentication.
What an attacker can do
03Attacker Capabilities
Inject malicious JavaScript that runs in admin and visitor browsers, stealing credentials or modifying site content.
Potential impact on your site
04Site Impact
Attackers can compromise admin accounts, deface your site, or inject malware visible to all visitors.
Conditions required to exploit
05Prerequisites
Network access to the WordPress site; no authentication or user interaction required.
Key dates
06Disclosure timeline
June 4, 2024
CVE published
April 28, 2026
Record updated