Continuous Image Carousel With Lightbox <= 1.0.15 - Reflected Cross-Site Scripting via search_term, order_by and order_pos
Strategic Overview
<= 1.0.15CVE-2023-28792Vulnerability Overview
The Continuous Image Carousel With Lightbox for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term, order_by and order_pos parameters in versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Please note there is not enough information to distinguish this from CVE-2023-28776.
Technical Analysis
REMEDIATION: Update to version 1.0.16, or a newer patched version --- IDENTIFIER: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C