The Comparison Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and including, 1.0.5. This makes it possible for authenticated attackers, with subscriber access or above, to change plugin settings and perform other actions such deleting sliders.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 15 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Wed, 12 Feb 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Comparisonslider
Comparisonslider comparison Slider |
|
Weaknesses | CWE-862 | |
CPEs | cpe:2.3:a:comparisonslider:comparison_slider:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Comparisonslider
Comparisonslider comparison Slider |

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-01T20:40:47.137Z
Reserved: 2024-05-02T12:10:12.111Z
Link: CVE-2024-4427

Updated: 2024-08-01T20:40:47.137Z

Status : Analyzed
Published: 2024-05-30T09:15:10.453
Modified: 2025-02-12T16:28:31.400
Link: CVE-2024-4427

No data.

No data.