CVE-2024-5429 is a critical vulnerability identified in the Logo Slider Free plugin, which is used by over 30,000 WordPress installations to create logo sliders. The flaw allows an attacker with contributor-level access to inject malicious JavaScript (JS) into the plugin’s settings, specifically in the “Brand Name” field. If exploited, this Stored Cross-Site Scripting (XSS) vulnerability can lead to admin account takeover and the creation of persistent backdoors, compromising the entire WordPress site.
CVE-2024-5429 – Logo Slider Free – Stored XSS to Admin Account Creation – POC
![CVE-2024-5429 – Logo Slider Free – Stored XSS to Admin Account Creation – POC CVE-2024-5429 – Logo Slider Free – Stored XSS to Admin Account Creation – POC](https://research.cleantalk.org/wp-content/uploads/2023/10/New_1_not_safe-1.png)