PT-2025-46279 · WordPress · Slider
Johska
·
Published
2025-11-11
·
Updated
2025-11-11
·
CVE-2025-12590
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
YSlider versions prior to 1.2
Description
The YSlider plugin for WordPress is susceptible to Cross-Site Request Forgery leading to Stored Cross-Site Scripting. This is a result of absent nonce verification on the content configuration page and inadequate input sanitization and output escaping. An unauthenticated attacker can inject arbitrary web scripts into pages by deceiving an administrator into performing an action, such as clicking a link. These injected scripts will execute whenever a user accesses the affected page.
Recommendations
Update YSlider to version 1.2 or later.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Slider