Slideshow 2.2.8 - 2.2.21 - Information Exposure

2015-05-02 00:00
Anonymous

Strategic Overview

Status
Patched in 2.2.22
Affected PluginSlideshow
Affected Version2.2.8 – 2.2.21
CVSS7.5High
CVECVE-2015-3634
View all Slideshow vulnerabilities

Vulnerability Overview

The SlideshowPluginSlideshowStylesheet::loadStylesheetByAJAX function in the Slideshow plugin 2.2.8 through 2.2.21 for Wordpress allows remote attackers to read arbitrary Wordpress option values.

Technical Analysis

REMEDIATION: Update to version 2.2.22, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C