Extension WordPress

Vulnérabilités Slide Anything – Responsive Content / HTML Slider and Carousel

Cette page rassemble les failles publiées pour Slide Anything – Responsive Content / HTML Slider and Carousel, leurs plages de versions affectées et les correctifs signalés dans la base locale.

3Vulnérabilités
0Critiques
3Avec correctif
6,4CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Slide Anything – Responsive Content / HTML Slider and Carousel

3 fiches

CVE-2023-28499 Moyenne · 6,4
Slide Anything – Responsive Content / HTML Slider and Carousel

Slide Anything <= 2.4.7 – Authenticated (Author+) Stored Cross-Site Scripting

The Slide Anything plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with author-level access, and…

Versions affectées

*-2.4.7

Correctif

2.4.9

Publication

15/03/2023

CVE-2022-2413 Moyenne · 5,5
Slide Anything – Responsive Content / HTML Slider and Carousel

Slide Anything – Responsive Content / HTML Slider and Carousel <= 2.3.46 – Authenticated (Admin+) Stored Cross-Site Scripting

The Slide Anything – Responsive Content / HTML Slider and Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title parameter in versions up to, and including, 2.3.46 due to insufficient input sanitization and…

Versions affectées

*-2.3.46

Correctif

2.3.47

Publication

06/07/2022

CVE-2022-1303 Moyenne · 5,5
Slide Anything – Responsive Content / HTML Slider and Carousel

Slide Anything – Responsive Content / HTML Slider and Carousel <= 2.3.43 – Editor+ Cross-Site Scripting

The Slide Anything WordPress plugin before 2.3.44 does not sanitize and escape sliders' description, which could allow high privilege users such as editor and above to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

Versions affectées

[*, 2.3.44)

Correctif

2.3.44

Publication

18/04/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités