CVE-2022-1320: Sliderby10Web < 1.2.52 - Admin+ Stored Cross-Site Scripting
The Sliderby10Web WordPress plugin before 1.2.52 does not properly sanitize and escape some of its settings, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfilteredhtml is disallowed
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-1320?
CVE-2022-1320 is a vulnerability in the Sliderby10Web WordPress plugin that allows high-privileged users to perform Cross-Site Scripting attacks.
How does CVE-2022-1320 impact the Sliderby10Web WordPress plugin?
CVE-2022-1320 allows high-privileged users, such as admin, to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.
What is the severity of CVE-2022-1320?
CVE-2022-1320 has a severity rating of medium (4.8).
How can I mitigate the CVE-2022-1320 vulnerability in the Sliderby10Web WordPress plugin?
To mitigate the CVE-2022-1320 vulnerability, update the Sliderby10Web plugin to version 1.2.52 or later, which properly sanitizes and escapes the settings.
Where can I find more information about CVE-2022-1320?
More information about CVE-2022-1320 can be found at https://wpscan.com/vulnerability/43581d6b-333a-48d9-a1ae-b9479da8ff87