WordPress plugin "Carousel Slider" provided by Sayful...
Moderate severity
Unreviewed
Published
Sep 2, 2024
to the GitHub Advisory Database
•
Updated Sep 4, 2024
Description
Published by the National Vulnerability Database
Sep 2, 2024
Published to the GitHub Advisory Database
Sep 2, 2024
Last updated
Sep 4, 2024
WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Hero image selection feature. While logged in to the WordPress site with Carousel Slider plugin enabled, accessing a crafted page may cause a user to alter the contents of the WordPress site.
References