PT-2024-10563 · WordPress · Team Circle Image Slider With Lightbox

Ala Arfaoui

·

Published

2024-03-13

·

Updated

2025-03-21

·

CVE-2015-10130

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Team Circle Image Slider With Lightbox plugin for WordPress version 1.0
Description The issue is due to missing or incorrect nonce validation on the circle thumbnail slider with lightbox image management func() function, making it possible for unauthenticated attackers to edit image data, which can be used to inject malicious JavaScript. Attackers can also delete images and upload malicious files via a forged request if they can trick a site administrator into performing an action such as clicking on a link.
Recommendations For version 1.0, consider disabling the circle thumbnail slider with lightbox image management func() function until a patch is available to prevent exploitation. Restrict access to image management functionality to minimize the risk of unauthorized edits or uploads.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-10130

Affected Products

Team Circle Image Slider With Lightbox