CVE-2023-24418: WordPress Tiny carousel horizontal slider plus Plugin <= 3.2 is vulnerable to Cross Site Scripting (XSS)
Published May 10, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Tiny carousel horizontal slider plus plugin <= 3.2 versions.
Affected Software
1 affected component
gopiplus Tiny Carousel Horizontal Slider Plus Wordpress<=3.2
Event History
May 10, 2023
CVE Published
via MITRE·07:43 AM
Data Sourced
via MITRE·07:43 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2023-24418.
2
What is the title of this vulnerability?
The title of this vulnerability is Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Tiny carousel horizontal slider plus plugin <= 3.2 versions.
3
What is the affected software?
The affected software is Gopiplus Tiny Carousel Horizontal Slider Plus plugin up to version 3.2.
4
What is the severity of this vulnerability?
The severity of this vulnerability is medium with a CVSS score of 4.8.
5
How can I fix this vulnerability?
To fix this vulnerability, it is recommended to update Gopiplus Tiny Carousel Horizontal Slider Plus plugin to a version higher than 3.2.