cvedb.io
CVE-2024-6026
MEDIUM · CVSS 5.4
EPSS exploitation probability: 0%
Published 2024-07-11T06:15:02.987 · Last modified 2026-06-17T08:17:08.320

Summary

The Slider by 10Web WordPress plugin before 1.2.56 does not sanitise and escape some of its Slide options, which could allow authenticated users with access to the Sliders (by default Administrator, however this can be changed via the Slider by 10Web WordPress plugin before 1.2.56's options) and the ability to add images (Editor+) to perform Stored Cross-Site Scripting attacks

Affected products

10web — slider

Does this affect you?

Add your gear to cvedb and we'll alert you only when 10web ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.