WordPress · Banner Cycler · CVE-2022-2233
**Name of the Vulnerable Software and Affected Versions**
Banner Cycler plugin for WordPress versions up to and including 1.4
**Description**
The issue is related to Cross-Site Request Forgery due to missing nonce protection on the `pabc admin slides postback()` function in the ~/admin/admin.php file. This allows unauthenticated attackers to inject malicious web scripts into the page if they can trick a site's administrator into performing a specific action, such as clicking on a link.
**Recommendations**
For Banner Cycler plugin for WordPress versions up to and including 1.4, consider disabling the `pabc admin slides postback()` function until a patch is available to prevent exploitation.