Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-88253
HistorySep 28, 2022 - 12:00 a.m.

WordPress Slider Hero cross-site scripting vulnerability

2022-09-2800:00:00
China National Vulnerability Database
www.cnvd.org.cn
4
wordpress
slider hero
cross-site scripting
vulnerability
php
unescaped slider names
administrators
attacks

0.001 Low

EPSS

Percentile

24.8%

WordPress and WordPress plugin are both products of the WordPress Foundation. WordPress is a set of blogging platforms developed using the PHP language. WordPress plugin is an application plugin. cross-site scripting vulnerability exists in versions prior to WordPress Slider Hero 8.4.4, which stems from unescaped slider names and can be exploited by attackers with high privileges, such as administrators, to launch cross-site scripting attacks.

CPENameOperatorVersion
wordpress slider herolt8.4.4

0.001 Low

EPSS

Percentile

24.8%