First published: Wed Jul 31 2024(Updated: )
The Slider by 10Web WordPress plugin before 1.2.57 does not sanitise and escape its Slider Title, which could allow high privilege users such as editors and above to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
10Web WordPress Slider | <1.2.57 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6408 is rated as a moderate severity vulnerability due to its potential for Cross-Site Scripting attacks.
To fix CVE-2024-6408, update the Slider by 10Web plugin to version 1.2.57 or later.
CVE-2024-6408 affects high privilege users such as editors and above on WordPress sites using versions of the Slider by 10Web plugin before 1.2.57.
CVE-2024-6408 is a Cross-Site Scripting (XSS) vulnerability due to improper sanitization and escaping of the Slider Title.
Yes, CVE-2024-6408 is fixed in the Slider by 10Web plugin version 1.2.57 and newer.