First published: Thu Apr 17 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dastan800 visualslider Sldier allows Reflected XSS. This issue affects visualslider Sldier: from n/a through 1.1.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
VisualSlider | <=1.1.1 | |
WordPress VisualSlider Slider Plugin | <=1.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23448 has been classified as a high-severity vulnerability due to its potential for reflected cross-site scripting attacks.
To fix CVE-2025-23448, update the visualslider Sldier plugin to version 1.1.2 or later, which addresses the reflected XSS vulnerability.
CVE-2025-23448 affects all versions of visualslider Sldier up to and including 1.1.1.
CVE-2025-23448 can facilitate reflected cross-site scripting attacks, which may allow adversaries to inject malicious scripts into the web pages viewed by users.
Yes, CVE-2025-23448 is applicable to the WordPress visualslider Sldier plugin up to version 1.1.1.