CVE-2024-32578: WordPress Sliderby10Web plugin <= 1.2.54 - Cross Site Scripting (XSS) vulnerability
Published Apr 18, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Slider by 10Web allows Reflected XSS.This issue affects Slider by 10Web: from n/a through 1.2.54.
Affected Software
4 affected components
10web Slider<=1.2.54
10web Slider by 10Web<=1.2.54
10web WordPress Slider by 10Web<=1.2.54
10web Slider Wordpress<1.2.55
Remediation
Information
Update to 1.2.55 or a higher version.
Event History
Apr 18, 2024
CVE Published
via MITRE·09:30 AM
Data Sourced
via MITRE·09:30 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-32578?
CVE-2024-32578 is classified as a moderate severity vulnerability due to its potential for exploitation via reflected cross-site scripting.
2
How do I fix CVE-2024-32578?
To mitigate CVE-2024-32578, users should update the 10Web Slider plugin to version 1.2.55 or later.
3
Which versions are affected by CVE-2024-32578?
CVE-2024-32578 affects Slider by 10Web versions up to and including 1.2.54.
4
What type of vulnerability is CVE-2024-32578?
CVE-2024-32578 is a Cross-site Scripting (XSS) vulnerability.
5
Who is affected by CVE-2024-32578?
Anyone using the Slider by 10Web plugin for WordPress versions up to 1.2.54 is affected by CVE-2024-32578.