s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

WORDFENCE-25762427-8d31-4fef-8b93-1065d15cd918 medium

📛 Threat Title

Slideshow < 2.1.13 - Cross-Site Scripting and Sensitive Information Disclosure

Category: wordpress-vulnerability Published: Source updated: First seen: Last updated: Source: Wordfence

Description

The Slideshow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 2.1.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The plugin is also vulnerable to Sensitive Data Exposure via several functions. This can allow unauthenticated attackers to extract sensitive data including the full file path of the WordPress installation. Affected software — plugin: Slideshow (affected: *-2.1.12). CVSS 6.1 (Medium) — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (2)

Remediations (1)

  • Wordfence remediation: Slideshow
    Wordfence

    Update to version 2.1.13, or a newer patched version

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.