WordPress Plugin Vulnerabilities

Slide Anything < 2.3.41 - Contributor+ SQLi

Description

The plugin does not sanitise and escape some parameters before using them in a SQL statement when duplicating Sliders, which could allow users with a role as low as Contributor to perform SQL injections

Affects Plugins

Fixed in 2.3.41

References

Classification

Type
SQLI
OWASP top 10
CWE
CVSS

Miscellaneous

Verified
Yes

Timeline

Publicly Published
2022-03-08 (about 3 years ago)
Added
2022-04-11 (about 3 years ago)
Last Updated
2022-04-11 (about 3 years ago)

Other