CVE-2024-45270
MEDIUMCarousel Slider < 2.2.4 - Cross-Site Request Forgery in Hero Image Selection
Title source: llmDescription
WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Hero image selection feature. While logged in to the WordPress site with Carousel Slider plugin enabled, accessing a crafted page may cause a user to alter the contents of the WordPress site.
References (3)
Core 3
Core References
Third Party Advisory
https://jvn.jp/en/jp/JVN25264194/
Scores
CVSS v3
4.3
EPSS
0.0022
EPSS Percentile
11.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-352
Status
published
Products (1)
majeedraza/carousel_slider
< 2.2.4
Published
Sep 02, 2024
Tracked Since
Feb 18, 2026