CVE-2024-3027 Information
Apr 14, 2024
cve
Description
The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the upload function in all versions up to and including 3.5.1.22. This makes it possible for authenticated attackers with contributor-level access and above to upload files including SVG files which can be used to conduct stored cross-site scripting attacks.
Reference
https://www.wordfence.com/threat-intel/vulnerabilities/id/915f464f-449d-4ad2-9f43-6ce5d93ccb05?source=cve https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3069057%40smart-slider-3&old=2996377%40smart-slider-3&sfp_email=&sfph_mail=
Share on: