Vulnerabilities > CM WP > Social Slider Widget > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-04-05 | CVE-2021-24196 | Cross-site Scripting vulnerability in Cm-Wp Social Slider Widget The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the ‘token_error’ parameter can be controlled by users and it is directly echoed without being sanitized | 5.4 |