Extension WordPress
Vulnérabilités Slide Anything – Responsive Content / HTML Slider and Carousel
Cette page rassemble les failles publiées pour Slide Anything – Responsive Content / HTML Slider and Carousel, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Slide Anything – Responsive Content / HTML Slider and Carousel
3 fiches
Slide Anything <= 2.4.7 – Authenticated (Author+) Stored Cross-Site Scripting
The Slide Anything plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with author-level access, and…
*-2.4.7
2.4.9
15/03/2023
Slide Anything – Responsive Content / HTML Slider and Carousel <= 2.3.46 – Authenticated (Admin+) Stored Cross-Site Scripting
The Slide Anything – Responsive Content / HTML Slider and Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title parameter in versions up to, and including, 2.3.46 due to insufficient input sanitization and…
*-2.3.46
2.3.47
06/07/2022
Slide Anything – Responsive Content / HTML Slider and Carousel <= 2.3.43 – Editor+ Cross-Site Scripting
The Slide Anything WordPress plugin before 2.3.44 does not sanitize and escape sliders' description, which could allow high privilege users such as editor and above to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
[*, 2.3.44)
2.3.44
18/04/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.