CVE-2021-24382 Information
Jun 07, 2022
cve
Description
The Smart Slider 3 Free and pro WordPress plugins before 3.5.0.9 did not sanitise the Project Name before outputting it back in the page leading to a Stored Cross-Site Scripting issue. By default only administrator users could access the affected functionality limiting the exploitability of the vulnerability. However some WordPress admins may allow lesser privileged users to access the plugin’s functionality in which case privilege escalation could be performed.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Reference
https://wpscan.com/vulnerability/7b32a282-e51f-4ee5-b59f-5ba10e62a54d https://smartslider.helpscoutdocs.com/article/1746-changelog
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
5.4
Share on: