CVE-2024-8283

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Sep 30, 2024
Updated: Oct 7, 2024
CWE ID 79

Summary

CVE-2024-8283 is a newly disclosed vulnerability affecting the Slider plugin by 10Web for WordPress. Before version 1.2.59, the plugin fails to sanitize and escape some of its settings, enabling high privilege users, including admins, to execute Stored Cross-Site Scripting attacks. This issue poses a significant risk, even in multisite setups where the unfiltered_html capability is disallowed. Attackers can inject malicious scripts into the plugin settings, leading to unintended functionality, data theft, or website defacement. Users are urged to upgrade to the latest version of the plugin to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share