Slide Anything – Responsive Content / HTML Slider and Carousel [slide-anything] < 2.3.47 (closed)
unknown
[en] The Slide Anything WordPress plugin before 2.3.47 does not properly sanitize or escape the slide title before outputting it in the admin pages, allowing a logged in user with roles as low as Author to inject a javascript payload into the slide title even when the unfiltered_html capability is disabled.
- Affected:
- up to 2.3.47
- Fixed in:
- 2.3.47
- Disclosed:
- Jan 16, 2024
CVE-2022-2413 on NVD →
Slide Anything – Responsive Content / HTML Slider and Carousel [slide-anything] < 2.4.9 (closed)
unknown
[en] Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in simonpedge Slide Anything – Responsive Content / HTML Slider and Carousel plugin <= 2.4.9 versions.
- Affected:
- up to 2.4.9
- Fixed in:
- 2.4.9
- Disclosed:
- Nov 7, 2023
CVE-2023-28499 on NVD →
Slide Anything <= 2.4.7 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Slide Anything plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with author-level access, and above, to inject arbitrary web scripts in pages that w...
- CVSS:
- 6.4
- Affected:
- up to 2.4.7
- Fixed in:
- 2.4.9
- Disclosed:
- Mar 15, 2023
CVE-2023-28499 on NVD →
Slide Anything – Responsive Content / HTML Slider and Carousel <= 2.3.46 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Slide Anything – Responsive Content / HTML Slider and Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title parameter in versions up to, and including, 2.3.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inj...
- CVSS:
- 5.5
- Affected:
- up to 2.3.46
- Fixed in:
- 2.3.47
- Disclosed:
- Jul 6, 2022
CVE-2022-2413 on NVD →
Slide Anything – Responsive Content / HTML Slider and Carousel [slide-anything] < 2.3.47 (closed)
unknown
The Slide Anything – Responsive Content / HTML Slider and Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title parameter in versions up to, and including, 2.3.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inj...
- Affected:
- up to 2.3.47
- Fixed in:
- 2.3.47
- Disclosed:
- Jul 6, 2022
Slide Anything – Responsive Content / HTML Slider and Carousel [slide-anything] < 2.3.44 (closed)
unknown
[en] The Slide Anything WordPress plugin before 2.3.44 does not sanitize and escape sliders' description, which could allow high privilege users such as editor and above to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
- Affected:
- up to 2.3.44
- Fixed in:
- 2.3.44
- Disclosed:
- May 9, 2022
CVE-2022-1303 on NVD →
Slide Anything – Responsive Content / HTML Slider and Carousel <= 2.3.43 - Editor+ Cross-Site Scripting
medium
The Slide Anything WordPress plugin before 2.3.44 does not sanitize and escape sliders' description, which could allow high privilege users such as editor and above to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
- CVSS:
- 5.5
- Affected:
- up to 2.3.44
- Fixed in:
- 2.3.44
- Disclosed:
- Apr 18, 2022
CVE-2022-1303 on NVD →
Slide Anything – Responsive Content / HTML Slider and Carousel [slide-anything] < 2.3.41 (closed)
unknown
Authenticated SQL Injection (SQLi) vulnerability discovered in WordPress Slide Anything plugin (versions <= 2.3.40).
- Affected:
- up to 2.3.41
- Fixed in:
- 2.3.41
- Disclosed:
- Mar 8, 2022
Slide Anything – Responsive Content / HTML Slider and Carousel [slide-anything] < 2.3.41 (closed)
unknown
The plugin does not sanitise and escape some parameters before using them in a SQL statement when duplicating Sliders, which could allow users with a role as low as Contributor to perform SQL injections
- Affected:
- up to 2.3.41
- Fixed in:
- 2.3.41
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database