CVE-2024-2306
The Slider Revolution plugin for WordPress before version 6.7.0 contains a cross-site scripting vulnerability that could be exploited by attackers to inject malicious scripts into websites. When visitors browse an affected site, these injected scripts could execute, potentially redirecting users, displaying unwanted advertisements, or executing arbitrary HTML payloads. The vulnerability was discovered by wesley (wcraft) and Nikolas - mdr and has been patched in version 6.7.0 and later.
Based on public CVE data (MITRE/NVD).