First published: Mon Sep 26 2022(Updated: )
The Slider Hero WordPress plugin before 8.4.4 does not escape the slider Name, which could allow high-privileged users to perform Cross-Site Scripting attacks.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Quantumcloud Slider Hero | <8.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3074 is a vulnerability in the Slider Hero WordPress plugin before version 8.4.4 that allows high-privileged users to perform Cross-Site Scripting attacks.
CVE-2022-3074 has a severity rating of 4.8, which is considered medium.
CVE-2022-3074 affects the Slider Hero WordPress plugin before version 8.4.4 by not properly escaping the slider Name, which could lead to Cross-Site Scripting attacks.
To fix CVE-2022-3074, you should update the Slider Hero WordPress plugin to version 8.4.4 or later, which includes the necessary fixes to escape the slider Name properly.
You can find more information about CVE-2022-3074 at the following reference link: [CVE-2022-3074](https://wpscan.com/vulnerability/90ebaedc-89df-413f-b22e-753d4dd5e1c3).