The Slider Hero WordPress plugin before 8.4.4 does not escape the slider Name, which could allow high-privileged users to perform Cross-Site Scripting attacks.
References
Link Resource
https://wpscan.com/vulnerability/90ebaedc-89df-413f-b22e-753d4dd5e1c3 Exploit Patch Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2022-09-26T12:35:41

Updated: 2022-09-26T12:35:41

Reserved: 2022-09-01T00:00:00


Link: CVE-2022-3074

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-09-26T13:15:11.013

Modified: 2022-09-27T03:43:55.640


Link: CVE-2022-3074

JSON object: View

cve-icon Redhat Information

No data.

CWE