WP Clinic
Entrar Registrarse

CVE · Medium

CVE-2024-12043 — Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.16.6

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2024-12043 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.16.6 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,4 < 3.16.6 3.16.6 2025-01-22

CVE-2024-12043

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Post Slider and Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'social_link_title' parameter of the 'blog' widget in all versions up to, and including, 3.16.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Escanea tu sitio WordPress gratis

Sin registro, sin tarjeta de crédito — ingresa tu URL y obtén un informe de seguridad en segundos.