CVE-2024-12308
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Feb 24, 2025
CWE ID 79
Summary
CVE-2024-12308: The Logo Slider WordPress plugin, prior to version 4.6.0, contains a vulnerability that fails to validate and properly escape some shortcode attributes. This issue poses a risk, allowing contributors and above to execute Stored Cross-Site Scripting attacks by injecting malicious code into pages or posts where the vulnerable shortcode is embedded.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share