cleantalk
Vulnerabilities and Security Researches

Thumbnail carousel slider, 3706ded923680765400114b00fd54bb18e696e43

Published on
Dec 28, 2020
Research Description
Thumbnail carousel slider [wp-responsive-thumbnail-slider] < 1.0.1 Thumbnail carousel slider < 1.0.1 - Stored Cross-Site Scripting and Cross-Site Request Forgery The Thumbnail carousel slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting and Cross-Site Request Forgery via the ‘title’ parameter in versions before 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The Stored Cross-Site scripting vulnerability requires authentication with admin-level privileges while the Cross-Site Request Forgery does not require any authentication.
Affected versions
max 1.0.1.
Status
vulnerable