CVE-2023-6382
- EPSS 0.27%
- Veröffentlicht 01.06.2024 05:15:08
- Zuletzt bearbeitet 07.01.2025 17:39:11
The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_slide' shortcode in all versions up to, and including, 3.9.9 due to insufficient input sanitization and output escaping...
CVE-2024-4470
- EPSS 0.23%
- Veröffentlicht 21.05.2024 07:15:08
- Zuletzt bearbeitet 07.01.2025 17:39:05
The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_slide_info' shortcode in all versions up to, and including, 3.9.9 due to insufficient input sanitization and output esc...
CVE-2024-32600
- EPSS 0.69%
- Veröffentlicht 18.04.2024 11:15:38
- Zuletzt bearbeitet 27.05.2025 16:45:15
Deserialization of Untrusted Data vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.9.5.
CVE-2024-32580
- EPSS 0.18%
- Veröffentlicht 18.04.2024 10:15:13
- Zuletzt bearbeitet 27.05.2025 16:44:58
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Master Slider allows Stored XSS.This issue affects Master Slider: from n/a through 3.9.8.
CVE-2024-1449
- EPSS 0.09%
- Veröffentlicht 02.03.2024 12:16:00
- Zuletzt bearbeitet 07.01.2025 17:38:57
The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ms_slide shortcode in all versions up to, and including, 3.9.5 due to insufficient input sanitization and output escaping o...
CVE-2024-0611
- EPSS 0.22%
- Veröffentlicht 02.03.2024 12:16:00
- Zuletzt bearbeitet 07.01.2025 17:38:50
The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slides callback functionality in all versions up to, and including, 3.9.5. This makes it possible for authenticated attackers, with ...
CVE-2023-6326
- EPSS 0.05%
- Veröffentlicht 02.03.2024 12:15:59
- Zuletzt bearbeitet 07.01.2025 17:39:16
The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.9.3. This is due to missing or incorrect nonce validation on the 'process_bulk_action' function. This...
CVE-2023-47508
- EPSS 0.1%
- Veröffentlicht 16.11.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:30:21
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Averta Master Slider Pro plugin <= 3.6.5 versions.
CVE-2018-20368
- EPSS 0.27%
- Veröffentlicht 23.12.2018 02:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:20
The Master Slider plugin 3.2.7 and 3.5.1 for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings value on Callback.