First published: Wed Jul 12 2023(Updated: )
The Slider Hero plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.2.0. This is due to missing or incorrect nonce validation on the qc_slider_hero_duplicate() function. This makes it possible for unauthenticated attackers to duplicate slides via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Credit: security@wordfence.com security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Quantumcloud Slider Hero | <=8.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this WordPress plugin is CVE-2021-4424.
The severity of CVE-2021-4424 is medium (4 out of 10).
The affected software is Quantumcloud Slider Hero WordPress plugin up to and including version 8.2.0.
The vulnerability is caused by missing or incorrect nonce validation on the qc_slider_hero_duplicate() function.
Attackers can exploit this vulnerability to duplicate slides via a forged request.