CVE-2024-8107

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Oct 1, 2024
Updated: Nov 13, 2024
CWE ID 79

Summary

CVE-2024-8107: The Slider Revolution plugin for WordPress, used by an estimated 1 million websites, suffers from a Stored Cross-Site Scripting (XSS) vulnerability. Attackers with Author-level access and above can exploit this issue by uploading maliciously crafted SVG files. The plugin fails to effectively sanitize and escape user inputs, leading to the execution of arbitrary web scripts within the pages visited by users accessing the affected files. By default, this vulnerability can only be exploited by administrators, but extended plugin capabilities can grant such privileges to authors.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share