WP Clinic
Log in Sign up

CVE · Medium

CVE-2024-12043 — Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.16.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-12043 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.16.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.16.6 3.16.6 2025-01-22

CVE-2024-12043

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Post Slider and Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'social_link_title' parameter of the 'blog' widget in all versions up to, and including, 3.16.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.