CVE-2024-8107
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-8107: The Slider Revolution plugin for WordPress, used by an estimated 1 million websites, suffers from a Stored Cross-Site Scripting (XSS) vulnerability. Attackers with Author-level access and above can exploit this issue by uploading maliciously crafted SVG files. The plugin fails to effectively sanitize and escape user inputs, leading to the execution of arbitrary web scripts within the pages visited by users accessing the affected files. By default, this vulnerability can only be exploited by administrators, but extended plugin capabilities can grant such privileges to authors.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.