CVE-2024-4581
The Slider Revolution plugin contains a stored cross-site scripting vulnerability in its Add Layer widget affecting versions up to 6.7.11, caused by inadequate sanitization and escaping of the 'class', 'id', and 'title' attributes. Authenticated users with author-level or higher permissions can inject malicious scripts into pages through these fields, and the scripts will execute for anyone viewing the affected pages. Exploitation depends on administrators first granting Slider Creation privileges to author-level users. The vulnerability was fixed in version 6.7.11.
Based on public CVE data (MITRE/NVD).