CVE · Medium

CVE-2024-8107 — Slider Revolution [revslider] < 6.7.19

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-8107 Slider Revolution [revslider] < 6.7.19 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 6.7.19 6.7.19 2024-09-30

CVE-2024-8107

A Stored Cross-Site Scripting vulnerability exists within the Slider Revolution plugin for WordPress due to inadequate handling of uploaded SVG files. Specifically, insufficient input validation allows malicious scripts to be embedded in these files, which are then executed when users access them. This flaw affects all versions up to and including 6.7.18, allowing attackers with Author-level permissions or higher to inject arbitrary web content.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.