Vulnerabilities > Majeedraza

DATE CVE VULNERABILITY TITLE RISK
2024-09-13 CVE-2024-6850 Cross-site Scripting vulnerability in Majeedraza Carousel Slider
The Carousel Slider WordPress plugin before 2.2.4 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
network
low complexity
majeedraza CWE-79
4.8
2024-09-02 CVE-2024-45269 Cross-Site Request Forgery (CSRF) vulnerability in Majeedraza Carousel Slider
WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Carousel image selection feature.
network
low complexity
majeedraza CWE-352
4.3
2024-09-02 CVE-2024-45270 Cross-Site Request Forgery (CSRF) vulnerability in Majeedraza Carousel Slider
WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Hero image selection feature.
network
low complexity
majeedraza CWE-352
4.3