First published: Mon Apr 15 2024(Updated: )
The Testimonial Slider WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Testimonial Slider | <2.3.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1746 is considered a high severity vulnerability due to the potential for Stored Cross-Site Scripting attacks.
To fix CVE-2024-1746, update the Testimonial Slider WordPress plugin to version 2.3.8 or later.
CVE-2024-1746 affects high privilege users, such as admins, using the Testimonial Slider plugin prior to version 2.3.8.
The risk associated with CVE-2024-1746 includes the ability for attackers to execute malicious scripts in the context of the user’s browser.
Yes, CVE-2024-1746 can be exploited in multisite environments even if the unfiltered_html capability is disallowed.