What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Image Slider Widget allows Stored XSS.This issue affects Image Slider Widget: from n/a through 1.1.125.
Explanation of Vulnerability in Simple Terms
02Summary
Image Slider Widget versions up to 1.1.125 contain a stored cross-site scripting (XSS) vulnerability. An authenticated administrator with high privileges can inject malicious scripts into slider content. When other users view the affected page, the script executes in their browser, potentially stealing session data or performing actions on their behalf. The vulnerability requires user interaction to trigger.
What an attacker can do
03Attacker Capabilities
Inject malicious scripts that execute when other users view the slider, stealing data or performing actions in their browser.
Potential impact on your site
04Site Impact
Administrators with high privileges can inject malicious code affecting all site visitors who view the slider.
Conditions required to exploit
05Prerequisites
Attacker must have high-level admin privileges and a user must view the affected slider content.
Key dates
06Disclosure timeline
April 24, 2024
CVE published
April 28, 2026
Record updated