PT-2024-16302 · WordPress · Logo Slider

Dmitry Ignatyev

·

Published

2024-11-28

·

Updated

2025-05-15

·

CVE-2024-10473

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Logo Slider WordPress plugin versions prior to 4.5.0
Description The issue concerns a Cross-Site Scripting vulnerability. It arises because the plugin does not properly sanitise and escape some of its Logo Settings when outputting them in pages where the Logo Slider shortcode is embedded. This could allow users with a role as low as Author to perform Cross-Site Scripting attacks.
Recommendations For versions prior to 4.5.0, update to version 4.5.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the Logo Slider shortcode to minimize the risk of exploitation. Additionally, limiting the role of users who can embed the shortcode can also help mitigate the risk until the update is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-10473

Affected Products

Logo Slider