The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the ‘token_error’ parameter can be controlled by users and it is directly echoed without being sanitized
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-08-03T19:21:18.781Z

Reserved: 2021-01-14T00:00:00

Link: CVE-2021-24196

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-04-05T19:15:16.827

Modified: 2024-11-21T05:52:34.350

Link: CVE-2021-24196

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.