Reflected XSS Vulnerability in Wp Slide Categorywise
CVE-2024-51690

7.1HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
9 November 2024

Summary

The Wp Slide Categorywise plugin by Neelam Samariya Thakor is susceptible to a reflected Cross-site Scripting (XSS) vulnerability. This flaw occurs due to improper neutralization of user input when generating web pages, allowing attackers to inject malicious scripts into the affected application. When exploited, this vulnerability can lead to unauthorized actions performed by users or expose sensitive information, making it critical for website administrators to ensure that input validation and sanitization procedures are in place. Affected versions include up to 1.1, emphasizing the need for prompt updates and security patches.

Affected Version(s)

Wp Slide Categorywise <= 1.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro Soares de Alcântara - Kinorth (Patchstack Alliance)
.