Stored Cross-Site Scripting Vulnerability in Category Post Slider Plugin for WordPress
CVE-2024-11878
Summary
CVE-2024-11878 identifies a stored cross-site scripting (XSS) vulnerability present in the Category Post Slider plugin for WordPress. This issue arises from inadequate input sanitization and output escaping within the plugin's 'category-post-slider' shortcode. As a result, authenticated attackers with contributor-level access or higher could exploit this vulnerability to inject arbitrary web scripts into affected pages. These scripts would execute whenever a user views the compromised page, potentially leading to unauthorized actions and exposure of sensitive information. Website administrators are strongly advised to update to the latest version of the plugin to mitigate this risk.
Affected Version(s)
Category Post Slider * <= 1.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved