Vulnerabilities > Shapedplugin > Logo Carousel > 3.2.9

DATE CVE VULNERABILITY TITLE RISK
2021-12-21 CVE-2021-24738 Cross-site Scripting vulnerability in Shapedplugin Logo Carousel
The Logo Carousel WordPress plugin before 3.4.2 does not validate and escape the "Logo Margin" carousel option, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks
3.5
2021-12-21 CVE-2021-24739 Authorization Bypass Through User-Controlled Key vulnerability in Shapedplugin Logo Carousel
The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arbitrary private posts made by other users via the Carousel Duplication feature
network
low complexity
shapedplugin CWE-639
8.1