cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forlogo-showcase-with-slick-slider logo-showcase-with-slick-slider

Direction: descending
Nov 15, 2024

Logo Showcase with Slick Slider – Logo Carousel, Logo Slider & Logo Grid # CVE-2022-4974

CVE, Research URL

CVE-2022-4974

Date
Oct 16, 2024
Research Description
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Affected versions
max 2.0.3.
Status
vulnerable
Jun 07, 2024

Logo Showcase with Slick Slider – Logo Carousel, Logo Slider & Logo Grid # CVE-2021-24730

CVE, Research URL

CVE-2021-24730

Date
Feb 28, 2022
Research Description
The Logo Showcase with Slick Slider WordPress plugin before 1.2.5 does not have CSRF and authorisation checks in the lswss_save_attachment_data AJAX action, allowing any authenticated users, such as Subscriber, to change title, description, alt text, and URL of arbitrary uploaded media.
Affected versions
max 2.0.3.
Status
vulnerable

Logo Showcase with Slick Slider – Logo Carousel, Logo Slider & Logo Grid # CVE-2021-24913

CVE, Research URL

CVE-2021-24913

Date
Feb 28, 2022
Research Description
The Logo Showcase with Slick Slider WordPress plugin before 2.0.1 does not have CSRF check in the lswss_save_attachment_data AJAX action, allowing attackers to make a logged in high privilege user, change title, description, alt text, and URL of arbitrary uploaded media.
Affected versions
max 2.0.3.
Status
vulnerable

Logo Showcase with Slick Slider – Logo Carousel, Logo Slider & Logo Grid # CVE-2021-24729

CVE, Research URL

CVE-2021-24729

Date
Nov 24, 2021
Research Description
The Logo Showcase with Slick Slider WordPress plugin before 1.2.4 does not sanitise the Grid Settings, which could allow users with a role as low as Author to perform stored Cross-Site Scripting attacks via post metadata of Grid logo showcase.
Affected versions
max 3.2.1.
Status
vulnerable