CVE · Medium

CVE-2021-24382 — Smart Slider 3 [smart-slider-3] < 3.5.0.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24382 Smart Slider 3 [smart-slider-3] < 3.5.0.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.5.0.9 3.5.0.9 2021-06-07

CVE-2021-24382

The Smart Slider 3 plugin versions prior to 3.5.0.9 failed to properly filter the Project Name parameter before displaying it on the page, creating a stored cross-site scripting vulnerability. Although administrator access was required by default to exploit this flaw, site owners who grant lower-privileged users access to the plugin could enable attackers to escalate their privileges through malicious input.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.