Stored Cross-Site Scripting Vulnerability in Category Post Slider Plugin for WordPress
CVE-2024-11878

6.4MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
20 December 2024

Summary

CVE-2024-11878 identifies a stored cross-site scripting (XSS) vulnerability present in the Category Post Slider plugin for WordPress. This issue arises from inadequate input sanitization and output escaping within the plugin's 'category-post-slider' shortcode. As a result, authenticated attackers with contributor-level access or higher could exploit this vulnerability to inject arbitrary web scripts into affected pages. These scripts would execute whenever a user views the compromised page, potentially leading to unauthorized actions and exposure of sensitive information. Website administrators are strongly advised to update to the latest version of the plugin to mitigate this risk.

Affected Version(s)

Category Post Slider * <= 1.4

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Thaleikis
.