CVE-2024-12173

CVSS 3.1 Score 3.5 of 10 (low)

Details

Published Feb 19, 2025
Updated: Feb 21, 2025

Summary

CVE-2024-12173 is a vulnerability affecting the Master Slider WordPress plugin before version 3.10.5. The issue arises from the plugin's failure to properly sanitize and escape some of its settings. This can allow high privilege users, such as Editors and above, to execute Stored Cross-Site Scripting attacks, even when the unfiltered_html capability is restricted, particularly in multisite setups. This vulnerability poses a significant security risk as it enables attackers to inject malicious scripts into a website, potentially leading to data theft, unauthorized access, or other malicious activities.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Master Slider Plugin

Affected Vendors

  • WordPress