CVE-2024-3703
03.05.2024, 06:15
The Carousel Slider WordPress plugin before 2.2.10 does not validate and escape some of its Slide options before outputting them back in the page/post where the related Slide shortcode is embed, which could allow users with the Editor role and above to perform Stored Cross-Site Scripting attacks
Vendor | Product | Version |
---|---|---|
majeedraza | carousel_slider | 𝑥 < 2.2.10 |
𝑥
= Vulnerable software versions