CVE · Medium

CVE-2024-8442 — Prime Slider – Hero Slider, Carousel, WooCommerce & Post Slider Elementor Addons [bdthemes-prime-slider-lite] < 3.15.19

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-8442 Prime Slider – Hero Slider, Carousel, WooCommerce & Post Slider Elementor Addons [bdthemes-prime-slider-lite] < 3.15.19 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.15.19 3.15.19 2024-11-06

CVE-2024-8442

The Prime Slider plugin for WordPress contains a vulnerability that allows attackers to inject malicious scripts into a website. This is due to inadequate protection against user input, allowing attackers to inject arbitrary web scripts that will execute when a user visits the affected page. The vulnerability affects all versions of the plugin up to and including 3.15.18, and requires only contributor-level access or higher to exploit.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.