WordPress · Wp Tripadvisor Review Slider · CVE-2023-6037
**Name of the Vulnerable Software and Affected Versions**
WP TripAdvisor Review Slider WordPress plugin versions prior to 11.9
**Description**
The WP TripAdvisor Review Slider WordPress plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered html capability is disallowed, for example in multisite setup.
**Recommendations**
For versions prior to 11.9, update to version 11.9 or later to resolve the issue. As a temporary workaround, consider restricting the ability of high privilege users to access and modify the plugin's settings until a patch is applied.