plugin

Cyclone Slider Vulnerabilities

1 known security issue reported for the Cyclone Slider WordPress plugin. Most recent disclosed Aug 5, 2022.

1 high

Running Cyclone Slider on your site? Check whether your installed version is affected.

Scan your site free

Cyclone Slider <= 3.2.0 - Authenticated (Admin+) Arbitrary File Upload

high

The Cyclone Slider Plugin is vulnerable to Remote Code Execution via the slider import functionality in versions up to, and including, 3.2.0, due to the use of the 'createfromimage' function as the sole method of validating file type. This allows authenticated users with administrative privileges to upload and extract...

CVSS:
7.2
Affected:
up to 3.2.0
Fix:
No patched version reported
Disclosed:
Aug 5, 2022

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database