Information Exposure in B Slider Plugin for WordPress
CVE-2024-13514
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 4 February 2025
What is CVE-2024-13514?
The B Slider plugin for WordPress contains a vulnerability that allows authenticated attackers with Contributor-level access and above to exploit insufficient restrictions on the 'bsb-slider' shortcode. This flaw allows them to access and extract sensitive data from private posts that should remain confidential. The issue arises in all versions of the plugin prior to 1.9.5, making it crucial for website administrators using this plugin to apply necessary updates to safeguard against unauthorized data access.
Affected Version(s)
B Slider- Gutenberg Slider Block for WP * <= 1.1.23