First published: Mon Jul 04 2022(Updated: )
The WP Contact Slider WordPress plugin before 2.4.7 does not sanitize and escape the Text to Display settings of sliders, which could allow high privileged users such as editor and above to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpexperts Wp Contact Slider | <2.4.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the WP Contact Slider WordPress plugin is CVE-2022-1301.
The severity of CVE-2022-1301 is medium.
The affected software for CVE-2022-1301 is the WP Contact Slider WordPress plugin versions up to and excluding 2.4.7.
The WP Contact Slider WordPress plugin can be exploited through Cross-Site Scripting (XSS) attacks.
Yes, high privileged users such as editor and above can perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.