PT-2024-30758 · WordPress · Slider/Carousel Slider By Depicter
Arkadiusz Hydzik
·
Published
2024-06-20
·
Updated
2024-07-17
·
CVE-2024-4390
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
The Slider and Carousel slider by Depicter plugin for WordPress versions up to, and including, 3.0.2
Description
The issue allows authenticated attackers with contributor access and above to generate a valid nonce for any WordPress action or function. This could be used to invoke functionality that is protected only by nonce checks.
Recommendations
For versions up to, and including, 3.0.2, update to a version that fixes the Arbitrary Nonce Generation issue to prevent exploitation.
As a temporary workaround, consider restricting contributor access and above to minimize the risk of exploitation.
Fix
Incorrect Authorization
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Slider/Carousel Slider By Depicter