Cross-Site Request Forgery Vulnerability in Image Slider With Lightbox Plugin
CVE-2015-10130
4.3MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 13 March 2024
What is CVE-2015-10130?
The Team Circle Image Slider With Lightbox plugin for WordPress possesses a vulnerability that allows unauthenticated attackers to exploit Cross-Site Request Forgery (CSRF) due to inadequate nonce validation in the circle_thumbnail_slider_with_lightbox_image_management_func() function. This security flaw can lead to unauthorized editing of image data, enabling attackers to inject malicious JavaScript code, delete images, and upload harmful files through forged requests. Attackers could leverage social engineering tactics to trick site administrators into executing such actions, further compromising the integrity of the site.
Affected Version(s)
Team Circle Image Slider With Lightbox 1.0