← Back

Wp Contact Slider

wp_contact_slider

Vendor: Wpexperts • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wpexperts
1Wp Contact Slider
May 6, 2025
Oct 31, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The WP Contact Slider WordPress plugin before 2.4.8 does not sanitize and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability...Show more
The WP Contact Slider WordPress plugin before 2.4.8 does not sanitize and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Wpexperts
1Wp Contact Slider
Nov 21, 2024
Jul 4, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WP Contact Slider WordPress plugin before 2.4.7 does not sanitize and escape the Text to Display settings of sliders, which could allow high privileged users such as editor and above to perform Cross-Site Scripting a...Show more
The WP Contact Slider WordPress plugin before 2.4.7 does not sanitize and escape the Text to Display settings of sliders, which could allow high privileged users such as editor and above to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowedShow less