Thumbnail carousel slider, ab7ac7d5-a68d-4af7-a38a-65aa940337f1
- CVE, Research URL
- Home page URL
- Application
- Published on
- -
- Research Description
- Responsive Thumbnail Slider [wp-responsive-thumbnail-slider] < 1.0.1 Thumbnail Carousel Slider < 1.0.1 - Stored Cross-Site Scripting (XSS) & CSRF The original advisory states that this vulnerability is exploitable with editor and author roles but this is incorrect. Only the administrator role by default can trigger this vulnerability. However, CSRF on the image upload form makes this exploitable by a malicious actor.
- Affected versions
-
max 1.0.1.
- Status
-
vulnerable