PT-2024-30758 · WordPress · Slider/Carousel Slider By Depicter

Arkadiusz Hydzik

·

Published

2024-06-20

·

Updated

2024-07-17

·

CVE-2024-4390

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Slider and Carousel slider by Depicter plugin for WordPress versions up to, and including, 3.0.2
Description The issue allows authenticated attackers with contributor access and above to generate a valid nonce for any WordPress action or function. This could be used to invoke functionality that is protected only by nonce checks.
Recommendations For versions up to, and including, 3.0.2, update to a version that fixes the Arbitrary Nonce Generation issue to prevent exploitation. As a temporary workaround, consider restricting contributor access and above to minimize the risk of exploitation.

Fix

Incorrect Authorization

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-4390

Affected Products

Slider/Carousel Slider By Depicter