Unknown Slider By 10Web vulnerabilities

6 known vulnerabilities affecting unknown/slider_by_10web.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM5

Vulnerabilities

Page 1 of 1
CVE-2024-10566MEDIUMCVSS 6.1fixed in 1.2.622025-03-25
CVE-2024-10566 [MEDIUM] CWE-79 CVE-2024-10566: The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its setting The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
cvelistv5nvd
CVE-2024-10565MEDIUMCVSS 6.1fixed in 1.2.622025-03-25
CVE-2024-10565 [MEDIUM] CWE-79 CVE-2024-10565: The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its setting The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
cvelistv5nvd
CVE-2024-8283MEDIUMCVSS 4.8fixed in 1.2.592024-09-30
CVE-2024-8283 [MEDIUM] CWE-79 CVE-2024-8283: The Slider by 10Web WordPress plugin before 1.2.59 does not sanitise and escape some of its setting The Slider by 10Web WordPress plugin before 1.2.59 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
cvelistv5nvd
CVE-2024-6408MEDIUMCVSS 5.4fixed in 1.2.572024-07-31
CVE-2024-6408 [MEDIUM] CWE-79 CVE-2024-6408: The Slider by 10Web WordPress plugin before 1.2.57 does not sanitise and escape its Slider Title, w The Slider by 10Web WordPress plugin before 1.2.57 does not sanitise and escape its Slider Title, which could allow high privilege users such as editors and above to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
cvelistv5nvd
CVE-2024-6026MEDIUMCVSS 5.4fixed in 1.2.562024-07-11
CVE-2024-6026 [MEDIUM] CWE-79 CVE-2024-6026: The Slider by 10Web WordPress plugin before 1.2.56 does not sanitise and escape some of its Slide o The Slider by 10Web WordPress plugin before 1.2.56 does not sanitise and escape some of its Slide options, which could allow authenticated users with access to the Sliders (by default Administrator, however this can be changed via the Slider by 10Web WordPress plugin before 1.2.56's options) and the ability to add images (Editor+) to perform Stored Cro
cvelistv5nvd
CVE-2021-24132HIGHCVSS 8.8≥ 1.2.36, < 1.2.362021-03-18
CVE-2021-24132 [HIGH] CWE-89 CVE-2021-24132: The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and sa The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and save_slider_db functionalities of the plugin were vulnerable, allowing a high privileged user (Admin), or medium one such as Contributor+ (if "Role Options" is turn on for other users) to perform a SQL Injection attacks.
cvelistv5nvd