Metrics
Affected Vendors & Products
Thu, 15 May 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Averta
Averta master Slider |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:averta:master_slider:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Averta
Averta master Slider |
Fri, 21 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 20 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 19 Feb 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Master Slider WordPress plugin before 3.10.5 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Title | Master Slider < 3.10.5 - Editor+ Stored XSS | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published: 2025-02-19T06:00:03.134Z
Updated: 2025-02-21T16:28:26.070Z
Reserved: 2024-12-04T15:34:51.700Z
Link: CVE-2024-12173
Updated: 2025-02-20T17:15:19.813Z
Status : Analyzed
Published: 2025-02-19T06:15:21.003
Modified: 2025-05-15T20:48:01.357
Link: CVE-2024-12173
No data.