CVE Published: 23/11/2021 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: WPScan |
Vendor: Unknown |
Product: Logo Showcase with Slick Slider – Logo Carousel, Logo Slider & Logo Grid Status : PUBLISHED
CVE-2021-24729 Description
The Logo Showcase with Slick Slider WordPress plugin before 1.2.4 does not sanitise the Grid Settings, which could allow users with a role as low as Author to perform stored Cross-Site Scripting attacks via post metadata of Grid logo showcase.