CVE-2021-4424: Slider Hero <= 8.2.0 - Cross-Site Request Forgery Bypass
The Slider Hero plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.2.0. This is due to missing or incorrect nonce validation on the qcsliderheroduplicate() function. This makes it possible for unauthenticated attackers to duplicate slides via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this WordPress plugin?
The vulnerability ID of this WordPress plugin is CVE-2021-4424.
What is the severity of CVE-2021-4424?
The severity of CVE-2021-4424 is medium (4 out of 10).
What is the affected software?
The affected software is Quantumcloud Slider Hero WordPress plugin up to and including version 8.2.0.
What is the cause of the vulnerability?
The vulnerability is caused by missing or incorrect nonce validation on the qc_slider_hero_duplicate() function.
How can attackers exploit this vulnerability?
Attackers can exploit this vulnerability to duplicate slides via a forged request.