Averta

Master Slider

19 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.27%
  • Veröffentlicht 01.06.2024 05:15:08
  • Zuletzt bearbeitet 07.01.2025 17:39:11

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_slide' shortcode in all versions up to, and including, 3.9.9 due to insufficient input sanitization and output escaping...

  • EPSS 0.23%
  • Veröffentlicht 21.05.2024 07:15:08
  • Zuletzt bearbeitet 07.01.2025 17:39:05

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_slide_info' shortcode in all versions up to, and including, 3.9.9 due to insufficient input sanitization and output esc...

  • EPSS 0.69%
  • Veröffentlicht 18.04.2024 11:15:38
  • Zuletzt bearbeitet 27.05.2025 16:45:15

Deserialization of Untrusted Data vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.9.5.

  • EPSS 0.18%
  • Veröffentlicht 18.04.2024 10:15:13
  • Zuletzt bearbeitet 27.05.2025 16:44:58

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Master Slider allows Stored XSS.This issue affects Master Slider: from n/a through 3.9.8.

  • EPSS 0.09%
  • Veröffentlicht 02.03.2024 12:16:00
  • Zuletzt bearbeitet 07.01.2025 17:38:57

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ms_slide shortcode in all versions up to, and including, 3.9.5 due to insufficient input sanitization and output escaping o...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 02.03.2024 12:16:00
  • Zuletzt bearbeitet 07.01.2025 17:38:50

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slides callback functionality in all versions up to, and including, 3.9.5. This makes it possible for authenticated attackers, with ...

  • EPSS 0.05%
  • Veröffentlicht 02.03.2024 12:15:59
  • Zuletzt bearbeitet 07.01.2025 17:39:16

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.9.3. This is due to missing or incorrect nonce validation on the 'process_bulk_action' function. This...

  • EPSS 0.1%
  • Veröffentlicht 16.11.2023 19:15:08
  • Zuletzt bearbeitet 21.11.2024 08:30:21

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Averta Master Slider Pro plugin <= 3.6.5 versions.

Exploit
  • EPSS 0.27%
  • Veröffentlicht 23.12.2018 02:29:00
  • Zuletzt bearbeitet 21.11.2024 04:01:20

The Master Slider plugin 3.2.7 and 3.5.1 for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings value on Callback.