Lucene search

K
wpvulndbWpvulndbWPVDB-ID:8AD662A8-E205-4160-AE2D-D1C115A6ED3A
HistoryNov 03, 2023 - 12:00 a.m.

Carousel, Recent Post Slider and Banner Slider < 2.1 - Contributor+ Stored Cross-Site Scripting

2023-11-0300:00:00
wpscan.com
5
cross-site scripting
stored
contributor+
injection
web scripts
shortcode
sanitize

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

24.4%

Description The plugin does not correctly sanitize and escape user-supplied attributes in the ‘spice_post_slider’ shortcode. This oversight could lead to the injection of arbitrary web scripts into pages that will execute whenever accessed by a user.

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

24.4%

Related for WPVDB-ID:8AD662A8-E205-4160-AE2D-D1C115A6ED3A