nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-6026 CVE-2024-6026
MEDIUM
Slider by 10Web < 1.2.56 - Editor+ Stored XSS
Record summary
CVE-2024-6026 has a selected CVSS score of 6.1 (medium).
Description
The Slider by 10Web WordPress plugin before 1.2.56 does not sanitise and escape some of its Slide options, which could allow authenticated users with access to the Sliders (by default Administrator, however this can be changed via the Slider by 10Web WordPress plugin before 1.2.56's options) and the ability to add images (Editor+) to perform Stored Cross-Site Scripting attacks
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 11, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
sliderBrowse 10web / sliderDefault status: unknown | CVE List | Before 1.2.56 | affected |
Slider by 10WebDefault status: unaffected | CVE List | Before 1.2.56 | affected |
References
2wpscan.comexploitvdb entryTechnical description
https://wpscan.com/vulnerability/01609d84-e9eb-46a9-b2cc-fe7e0c982984