CVE · Medium

CVE-2024-3027 — Smart Slider 3 [smart-slider-3] < 3.5.1.23

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-3027 Smart Slider 3 [smart-slider-3] < 3.5.1.23 Improper Authorization Medium 6.4 < 3.5.1.23 3.5.1.23 2024-04-12

CVE-2024-3027

The Smart Slider 3 plugin through version 3.5.1.22 fails to properly verify user permissions before allowing file uploads, permitting contributors and higher-privileged users to upload files such as SVG images that can execute stored cross-site scripting attacks. This capability check absence enables authenticated attackers to modify data and inject malicious content into the WordPress site.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.