CVE-2024-13627
CVSS 3.1 Score 4.7 of 10 (medium)
Details
Summary
CVE-2024-13627 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the OWL Carousel Slider WordPress plugin up to version 2.2. This issue arises due to the plugin's failure to sanitize and escape an input parameter before rendering it on the page. An attacker can exploit this flaw by injecting malicious scripts into the affected page, potentially gaining unauthorized access or stealing sensitive information from high privilege users, such as administrators. Users are advised to update the plugin to the latest version or consider using alternative, more secure plugins to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.