First published: Sun Dec 23 2018(Updated: )
The Master Slider plugin 3.2.7 and 3.5.1 for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings value on Callback.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Averta Master Slider | =3.2.7 | |
Averta Master Slider | =3.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Master Slider plugin vulnerability is CVE-2018-20368.
The severity of CVE-2018-20368 is medium with a CVSS score of 5.4.
The Master Slider plugin 3.2.7 and 3.5.1 for WordPress is affected by this vulnerability through the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings value on Callback.
The affected software for CVE-2018-20368 is Averta Master Slider version 3.2.7 and 3.5.1 on WordPress.
To fix CVE-2018-20368, update the Master Slider plugin to a version that includes the security patch.