Unauthorized Data Modification Vulnerability in Smart Slider 3 Plugin
CVE-2024-3027
6.4MEDIUM
What is CVE-2024-3027?
The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the upload function in all versions up to, and including, 3.5.1.22. This makes it possible for authenticated attackers, with contributor-level access and above, to upload files, including SVG files, which can be used to conduct stored cross-site scripting attacks.
Affected Version(s)
Smart Slider 3 * <= 3.5.1.22