Information Exposure in B Slider Plugin for WordPress
CVE-2024-13514
4.3MEDIUM
Key Information:
- Vendor
- Bplugins
- Status
- B Slider- Gutenberg Slider Block For WP
- Vendor
- CVE Published:
- 4 February 2025
Summary
The B Slider plugin for WordPress contains a vulnerability that allows authenticated attackers with Contributor-level access and above to exploit insufficient restrictions on the 'bsb-slider' shortcode. This flaw allows them to access and extract sensitive data from private posts that should remain confidential. The issue arises in all versions of the plugin prior to 1.9.5, making it crucial for website administrators using this plugin to apply necessary updates to safeguard against unauthorized data access.
Affected Version(s)
B Slider- Gutenberg Slider Block for WP * <= 1.1.23
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nirmal