Back to search
CVE-2021-24196
Published: Apr 5, 2021
Modified: Aug 3, 2024
PUBLISHED
Description
The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the ‘token_error’ parameter can be controlled by users and it is directly echoed without being sanitized
| Vendor | Product | Versions |
|---|---|---|
Unknown | Social Slider Widget | affected 1.8.5 - < 1.8.5 |
Weaknesses (CWE)
References
https://wpscan.com/vulnerability/bb20d732-a5e4-4140-ab51-b2aa1a53db12
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now