Information Exposure in B Slider Plugin for WordPress
CVE-2024-13514
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 4 February 2025
What is CVE-2024-13514?
The B Slider plugin for WordPress contains a vulnerability that allows authenticated attackers with Contributor-level access and above to exploit insufficient restrictions on the 'bsb-slider' shortcode. This flaw allows them to access and extract sensitive data from private posts that should remain confidential. The issue arises in all versions of the plugin prior to 1.9.5, making it crucial for website administrators using this plugin to apply necessary updates to safeguard against unauthorized data access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
B Slider- Gutenberg Slider Block for WP * <= 1.1.23
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved