The Logo Showcase with Slick Slider WordPress plugin...
Moderate severity
Unreviewed
Published
Nov 24, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Nov 23, 2021
Published to the GitHub Advisory Database
Nov 24, 2021
Last updated
Feb 1, 2023
The Logo Showcase with Slick Slider WordPress plugin before 1.2.4 does not sanitise the Grid Settings, which could allow users with a role as low as Author to perform stored Cross-Site Scripting attacks via post metadata of Grid logo showcase.
References