CVE-2021-24382: Smart Slider 3 < 3.5.0.9 - Authenticated Stored Cross-Site Scripting (XSS)
The Smart Slider 3 Free and pro WordPress plugins before 3.5.0.9 did not sanitise the Project Name before outputting it back in the page, leading to a Stored Cross-Site Scripting issue. By default, only administrator users could access the affected functionality, limiting the exploitability of the vulnerability. However, some WordPress admins may allow lesser privileged users to access the plugin's functionality, in which case, privilege escalation could be performed.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24382?
CVE-2021-24382 is considered a moderate severity vulnerability due to its potential exploitation through stored cross-site scripting.
How do I fix CVE-2021-24382?
To fix CVE-2021-24382, update the Smart Slider 3 plugin to version 3.5.0.9 or later.
Who is affected by CVE-2021-24382?
CVE-2021-24382 affects both the free and pro versions of the Smart Slider 3 plugin prior to version 3.5.0.9.
What type of vulnerability is CVE-2021-24382?
CVE-2021-24382 is a stored cross-site scripting vulnerability due to improper sanitization of user input.
Can non-administrator users exploit CVE-2021-24382?
By default, only administrator users have access to the affected functionality, limiting the exploit potential for non-administrator users.