The Carousel Slider WordPress plugin before 2.2.10 does not validate and escape some of its Slide options before outputting them back in the page/post where the related Slide shortcode is embed, which could allow users with the Editor role and above to perform Stored Cross-Site Scripting attacks
Metrics
Affected Vendors & Products
References
History
Thu, 10 Apr 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:majeedraza:carousel_slider:*:*:*:*:*:wordpress:*:* |
Fri, 29 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Majeedraza
Majeedraza carousel Slider |
|
CPEs | cpe:2.3:a:majeedraza:carousel_slider:*:*:*:*:*:*:*:* | |
Vendors & Products |
Majeedraza
Majeedraza carousel Slider |
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-11-29T15:40:28.767Z
Reserved: 2024-04-12T10:00:04.255Z
Link: CVE-2024-3703

Updated: 2024-08-01T20:20:00.768Z

Status : Analyzed
Published: 2024-05-03T06:15:14.800
Modified: 2025-04-10T14:00:48.770
Link: CVE-2024-3703

No data.