CVE-2023-0660: Smart Slider 3 < 3.5.1.14 - Contributor+ Stored XSS
The Smart Slider 3 WordPress plugin before 3.5.1.14 does not properly validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0660?
CVE-2023-0660 has a medium severity rating due to potential Stored Cross-Site Scripting vulnerabilities.
How do I fix CVE-2023-0660?
To fix CVE-2023-0660, update the Smart Slider 3 plugin to version 3.5.1.14 or later.
What is the impact of CVE-2023-0660?
The impact of CVE-2023-0660 allows users with the contributor role and above to exploit Cross-Site Scripting vulnerabilities.
Who is affected by CVE-2023-0660?
Users of the Smart Slider 3 plugin prior to version 3.5.1.14 are affected by CVE-2023-0660.
What are the possible exploit scenarios for CVE-2023-0660?
Possible exploit scenarios for CVE-2023-0660 include injecting malicious scripts through shortcode attributes.