Stored Cross-Site Scripting in Carousel, Slider, Gallery Plugin by WP Carousel
CVE-2024-4002
What is CVE-2024-4002?
The Carousel, Slider, Gallery by WP Carousel plugin for WordPress before version 2.6.9 lacks proper sanitization and escaping of certain settings. This flaw can be exploited by high-privilege users, such as administrators, to carry out Stored Cross-Site Scripting (XSS) attacks. Even in a multisite configuration where unfiltered HTML input is generally restricted, the vulnerability allows an attacker to inject malicious scripts, potentially compromising site security and integrity.
Affected Version(s)
Carousel, Slider, Gallery by WP Carousel 0 < 2.6.9
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved