plugin

Wp Vertical Image Slider Vulnerabilities

4 known security issues reported for the Wp Vertical Image Slider WordPress plugin. Most recent disclosed May 9, 2023.

1 high 3 medium

Running Wp Vertical Image Slider on your site? Check whether your installed version is affected.

Scan your site free

wordpress vertical image slider plugin <= 1.2.16 - Reflected Cross-Site Scripting

medium

The wordpress vertical image slider plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will ex...

CVSS:
6.1
Affected:
up to 1.2.16
Fixed in:
1.2.17
Disclosed:
May 9, 2023

CVE-2023-24413 on NVD →

wordpress vertical image slider plugin <= 1.2.16 - Reflected Cross-Site Scripting

medium

The wordpress vertical image slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_term’ parameter in versions up to, and including, 1.2.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...

CVSS:
6.1
Affected:
up to 1.2.16
Fixed in:
1.2.17
Disclosed:
Apr 25, 2023

CVE-2023-2289 on NVD →

wordpress vertical image slider plugin < 1.2 - Cross-Site Scripting

medium

The wordpress vertical image slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘imagetitle’ and ‘imageurl’ parameters in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitra...

CVSS:
6.1
Affected:
up to 1.2
Fixed in:
1.2
Disclosed:
Sep 19, 2015

wordpress vertical image slider plugin < 1.2 - Cross-Site Request Forgery

high

The "wordpress vertical image slider plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery via several functions in versions up to, and including, 1.0. This makes it possible for unauthenticated attackers to upload malicious files among other actions granted they can trick a site's administrator into...

CVSS:
8.8
Affected:
up to 1.2
Fixed in:
1.2
Disclosed:
Aug 2, 2015

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database