CVE · Medium

CVE-2024-2306 — Slider Revolution [revslider] < 6.7.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-2306 Slider Revolution [revslider] < 6.7.0 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) Medium 6.4 < 6.7.0 6.7.0 2024-04-08

CVE-2024-2306

The Slider Revolution plugin for WordPress before version 6.7.0 contains a cross-site scripting vulnerability that could be exploited by attackers to inject malicious scripts into websites. When visitors browse an affected site, these injected scripts could execute, potentially redirecting users, displaying unwanted advertisements, or executing arbitrary HTML payloads. The vulnerability was discovered by wesley (wcraft) and Nikolas - mdr and has been patched in version 6.7.0 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.