Fluid Responsive Slideshow < 2.2.7 - Cross-Site Request Forgery
highThe fluid-responsive-slideshow plugin before 2.2.7 for WordPress has frs_save CSRF bug with Reflected XSS.
- CVSS:
- 8.8
- Affected:
- up to 2.2.7
- Fixed in:
- 2.2.7
- Disclosed:
- May 18, 2016
plugin
3 known security issues reported for the Fluid Responsive Slideshow WordPress plugin. Most recent disclosed May 18, 2016.
Running Fluid Responsive Slideshow on your site? Check whether your installed version is affected.
Scan your site freeThe fluid-responsive-slideshow plugin before 2.2.7 for WordPress has frs_save CSRF bug with Reflected XSS.
The Fluid Responsive Slideshow plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.6. This is due to missing or incorrect nonce validation on the frst_save() function. This makes it possible for unauthenticated attackers to edit content on all pages and posts via a for...
The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has reflected XSS via the skin parameter.
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free