CVE-2024-12173: Master Slider < 3.10.5 - Editor+ Stored XSS
The Master Slider WordPress plugin before 3.10.5 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor and above to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12173?
CVE-2024-12173 is classified as a medium severity vulnerability due to its potential for Stored Cross-Site Scripting attacks by high privilege users.
How do I fix CVE-2024-12173?
To fix CVE-2024-12173, update the Master Slider WordPress plugin to version 3.10.5 or later.
Who is affected by CVE-2024-12173?
CVE-2024-12173 affects users of the Master Slider WordPress plugin version prior to 3.10.5, particularly those with high privilege roles like Editor and above.
What types of attacks can CVE-2024-12173 facilitate?
CVE-2024-12173 can facilitate Stored Cross-Site Scripting (XSS) attacks, allowing malicious scripts to be executed on affected sites.
Can CVE-2024-12173 be exploited in a multisite setup?
Yes, CVE-2024-12173 can be exploited in a multisite setup even when the unfiltered_html capability is disallowed.