WordPress LayerSlider Plugin 7.11.0 is vulnerable to Cross Site Scripting (XSS)
LayerSlider
Minimum safe version
7.11.1
Update to 7.11.1 or later to address 15 fixable vulnerabilities
CVE-2024-2879
CVE-2023-47785
CVE-2023-47786
LayerSlider 4.6.1 - Style Editing CSRF
LayerSlider 4.6.1 - Remote Path Traversal File Access
LayerSlider <= 6.2.0 - CSRF / Authenticated Stored XSS & SQL Injection
LayerSlider <= 4.6.1 - Path Traversal
LayerSlider <= 4.6.1 - Cross-Site Request Forgery
LayerSlider <= 6.2.0 - Cross-Site Request Forgery
LayerSlider <= 6.2.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting
WordPress LayerSlider Plugin <= 4.6.1 - Remote Path Traversal File Access
WordPress LayerSlider Plugin <= 4.6.1 - Cross Site Request Forgery
WordPress LayerSlider plugin <=6.2.0 - Cross-Site Request Forgery (CSRF) vulnerability
CVE-2022-1153