Lucene search

K
patchstackNgo Van Thien (Patchstack Alliance)PATCHSTACK:DD0C131D19824DB4E64EAE7D4F0FDA82
HistoryMay 26, 2022 - 12:00 a.m.

WordPress Promotion Slider plugin <= 3.3.4 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities

2022-05-2600:00:00
Ngo Van Thien (Patchstack Alliance)
patchstack.com
13
wordpress promotion slider
cross-site scripting
ngo van thien
patchstack alliance
deactivate
delete
download.

EPSS

0.001

Percentile

22.7%

Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities were discovered by Ngo Van Thien (Patchstack Alliance) in the WordPress Promotion Slider plugin (versions <= 3.3.4).

Solution

Deactivate and delete. This plugin has been closed as of May 20, 2022 and is not available for download. This closure is temporary, pending a full review.

EPSS

0.001

Percentile

22.7%

Related for PATCHSTACK:DD0C131D19824DB4E64EAE7D4F0FDA82