CVE-2024-13314: Carousel, Slider, Gallery by WP Carousel < 2.7.4 - Admin+ Stored XSS
The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.7.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13314?
The severity of CVE-2024-13314 is classified as high due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-13314?
To fix CVE-2024-13314, update the WP Carousel plugin to version 2.7.4 or later.
Who is affected by CVE-2024-13314?
CVE-2024-13314 affects users of the WP Carousel, Slider, Gallery plugin prior to version 2.7.4.
What are Stored Cross-Site Scripting attacks related to CVE-2024-13314?
Stored Cross-Site Scripting attacks allow malicious users to inject scripts that can execute in the context of other users visiting the site.
Is there a patch available for CVE-2024-13314?
Yes, a patch is available in the form of an update to the plugin, which resolves the vulnerability.