Vulnerabilities > CM WP > Social Slider Widget > 1.6.2

DATE CVE VULNERABILITY TITLE RISK
2021-04-05 CVE-2021-24196 Cross-site Scripting vulnerability in Cm-Wp Social Slider Widget
The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the ‘token_error’ parameter can be controlled by users and it is directly echoed without being sanitized
network
low complexity
cm-wp CWE-79
5.4