Stored Cross-Site Scripting Vulnerability in Prime Slider for WordPress
CVE-2024-12043
6.4MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 23 January 2025
Summary
The Prime Slider – Addons For Elementor plugin for WordPress is susceptible to a stored Cross-Site Scripting (XSS) vulnerability due to inadequate input sanitization and output escaping in the 'social_link_title' parameter of the 'blog' widget. This issue affects all versions up to and including 3.16.5, permitting authenticated users with Contributor-level access or higher to introduce malicious web scripts. These scripts can execute whenever other users access the manipulated pages, creating significant security risks and potential exploits.
Affected Version(s)
Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Post Slider and Ecommerce Slider) * <= 3.16.5
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
D.Sim