CVE-2024-11221: Full Screen (Page) Background Image Slideshow <= 1.1 - Admin+ Stored XSS
The Full Screen (Page) Background Image Slideshow WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11221?
CVE-2024-11221 is classified as a high severity vulnerability due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-11221?
To fix CVE-2024-11221, update the Full Screen (Page) Background Image Slideshow plugin to the latest version, ensuring that all user inputs are properly sanitized and escaped.
Who is affected by CVE-2024-11221?
CVE-2024-11221 affects users of the Full Screen (Page) Background Image Slideshow plugin for WordPress up to version 1.1.
What types of attacks are possible with CVE-2024-11221?
CVE-2024-11221 allows high privilege users to perform Stored Cross-Site Scripting attacks, which can compromise site security.
What are the consequences of exploiting CVE-2024-11221?
Exploiting CVE-2024-11221 could lead to unauthorized script execution in a user's browser, allowing attackers to steal cookies, session tokens, or other sensitive information.