WordPress video carousel slider with lightbox Plugin <= 1.0.22 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-32797
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 August 2023
What is CVE-2023-32797?
An unauthenticated reflected Cross-Site Scripting (XSS) vulnerability exists in the Video Carousel Slider with Lightbox plugin by I Thirteen Web Solution, affecting versions up to 1.0.22. This flaw allows attackers to inject malicious scripts via manipulated requests, potentially compromising the security of users interacting with the plugin.
Affected Version(s)
video carousel slider with lightbox <= 1.0.22