CVE-2024-6490: Master Slider – Responsive Touch Slider <= 3.9.10 - CSRF to slider deletion
During testing of the Master Slider WordPress plugin through 3.9.10, a CSRF vulnerability was found, which allows an unauthorized user to manipulate requests on behalf of the victim and thereby delete all of the sliders inside Master Slider WordPress plugin through 3.9.10.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6490?
CVE-2024-6490 has a moderate severity level due to the potential for unauthorized users to delete sliders.
How do I fix CVE-2024-6490?
To mitigate CVE-2024-6490, users should update the Master Slider WordPress plugin to a version beyond 3.9.10.
What type of vulnerability is CVE-2024-6490?
CVE-2024-6490 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
Who is affected by CVE-2024-6490?
Users of the Master Slider WordPress plugin version 3.9.10 are affected by CVE-2024-6490.
What can an attacker do with CVE-2024-6490?
An attacker can exploit CVE-2024-6490 to delete all sliders from the Master Slider WordPress plugin on behalf of the victim.