Slideshow, Image Slider by 2J <= 1.3.54 - Reflected Cross-Site Scripting via 'post'
medium
The Slideshow, Image Slider by 2J plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘post’ parameter in versions up to, and including, 1.3.54 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...
- CVSS:
- 6.1
- Affected:
- up to 1.3.54
- Fix:
- No patched version reported
- Disclosed:
- Aug 16, 2024
CVE-2023-4604 on NVD →
Slideshow, Image Slider by 2J <= 1.3.54 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Slideshow, Image Slider by 2J plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.54 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permiss...
- CVSS:
- 6.4
- Affected:
- up to 1.3.54
- Fix:
- No patched version reported
- Disclosed:
- Sep 29, 2023
CVE-2023-44242 on NVD →
Slideshow, Image Slider by 2J <= 1.3.54 - Reflected Cross-Site Scripting
medium
Authenticated (contributor or higher user role) Reflected Cross-Site Scripting (XSS) vulnerability in 2J Slideshow Team's Slideshow, Image Slider by 2J plugin <= 1.3.54 at WordPress.
- CVSS:
- 5.4
- Affected:
- up to 1.3.54
- Fix:
- No patched version reported
- Disclosed:
- May 4, 2022
CVE-2022-29426 on NVD →
Slideshow, Image Slider by 2J <= 1.3.31 - Authorization Bypass
medium
The 2J-SlideShow Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'twoj_slideshow_setup' function called via the wp_ajax_twoj_slideshow_setup AJAX action in versions up to, and including, 1.3.31. This makes it possible for authenticated attackers (Subscriber, or above...
- CVSS:
- 5.4
- Affected:
- up to 1.3.31
- Fixed in:
- 1.3.33
- Disclosed:
- Jan 20, 2020
CVE-2020-36729 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database