CVE-2024-6408: Slider by 10Web < 1.2.57 - Editor+ Stored XSS
The Slider by 10Web WordPress plugin before 1.2.57 does not sanitise and escape its Slider Title, which could allow high privilege users such as editors and above to perform Cross-Site Scripting attacks even when unfilteredhtml is disallowed
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6408?
CVE-2024-6408 is rated as a moderate severity vulnerability due to its potential for Cross-Site Scripting attacks.
How do I fix CVE-2024-6408?
To fix CVE-2024-6408, update the Slider by 10Web plugin to version 1.2.57 or later.
Who is impacted by CVE-2024-6408?
CVE-2024-6408 affects high privilege users such as editors and above on WordPress sites using versions of the Slider by 10Web plugin before 1.2.57.
What type of vulnerability is CVE-2024-6408?
CVE-2024-6408 is a Cross-Site Scripting (XSS) vulnerability due to improper sanitization and escaping of the Slider Title.
Is CVE-2024-6408 fixed in later versions?
Yes, CVE-2024-6408 is fixed in the Slider by 10Web plugin version 1.2.57 and newer.