WordPress Plugin Vulnerabilities

Logo Slider < 4.5.0 - Contributor+ Stored XSS

Description

The plugin does not sanitise and escape some of its Logo and Slider settings, which could allow high privilege users such as Contributor to perform Stored Cross-Site Scripting

Proof of Concept

Affects Plugins

Fixed in 4.5.0

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Dmitrii Ignatyev
Submitter
Dmitrii Ignatyev
Verified
Yes

Timeline

Publicly Published
2024-11-07 (about 1 year ago)
Added
2024-11-07 (about 1 year ago)
Last Updated
2024-11-07 (about 1 year ago)

Other