cleantalk
Vulnerabilities and Security Researches

Thumbnail carousel slider, CVE-2023-1915

CVE, Research URL

CVE-2023-1915

Published on
May 15, 2023
Research Description
The Thumbnail carousel slider WordPress plugin before 1.1.10 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting vulnerability which could be used against high privilege users such as admin.
Affected versions
Min -, max 1.0.1.
Status
vulnerable