CVE-2024-35775 MEDIUM

CVE-2024-35775: WordPress Slider by Soliloquy plugin <= 2.7.6 - Broken Access Control to XSS vulnerability

Vendor Soliloquy Team
Product Slider by Soliloquy
Weakness CWE-79 · XSS
Published August 12, 2024
Last update April 28, 2026

CVSS base score

5.9/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Authentication vulnerability in Soliloquy Team Slider by Soliloquy allows Cross-Site Scripting (XSS).This issue affects Slider by Soliloquy: from n/a through 2.7.6.

Explanation of Vulnerability in Simple Terms

02Summary

Slider by Soliloquy versions up to 2.7.6 contain a cross-site scripting (XSS) vulnerability that allows authenticated users with high privileges to inject malicious scripts. The vulnerability requires user interaction to trigger. An attacker with admin or editor access can craft a malicious slider configuration that executes JavaScript in the browsers of site visitors, potentially compromising user sessions or stealing data.

What an attacker can do

03Attacker Capabilities

Inject and execute malicious JavaScript in visitor browsers through slider content.

Potential impact on your site

04Site Impact

Compromised admin accounts can inject malicious code affecting all site visitors.

Conditions required to exploit

05Prerequisites

Admin or editor access to the site; victim must view the affected slider.

Key dates

06Disclosure timeline

August 12, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE