Cross-Site Scripting in Master Slider Plugin for WordPress by Magenest
CVE-2018-20368
5.4MEDIUM
What is CVE-2018-20368?
The Master Slider plugin for WordPress, specifically versions 3.2.7 and 3.5.1, is susceptible to a Cross-Site Scripting (XSS) vulnerability. This security flaw arises due to improper handling of user input through the wp-admin/admin-ajax.php endpoint. An attacker can exploit this vulnerability by injecting malicious scripts via the Name input field within the MSPanel.Settings configuration, potentially allowing unauthorized access and control over affected installations.