Stored Cross-Site Scripting Vulnerability in Category Post Slider Plugin for WordPress
CVE-2024-11878
6.4MEDIUM
What is CVE-2024-11878?
CVE-2024-11878 identifies a stored cross-site scripting (XSS) vulnerability present in the Category Post Slider plugin for WordPress. This issue arises from inadequate input sanitization and output escaping within the plugin's 'category-post-slider' shortcode. As a result, authenticated attackers with contributor-level access or higher could exploit this vulnerability to inject arbitrary web scripts into affected pages. These scripts would execute whenever a user views the compromised page, potentially leading to unauthorized actions and exposure of sensitive information. Website administrators are strongly advised to update to the latest version of the plugin to mitigate this risk.
Affected Version(s)
Category Post Slider * <= 1.4