CVE-2024-45269

Published
View on NVD ↗
CVSS v3
4.3
MEDIUM
CVSS v2
N/A
Affected
2
PROJECTS

Description

WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Carousel image selection feature. While logged in to the WordPress site with Carousel Slider plugin enabled, accessing a crafted page may cause a user to alter the contents of the WordPress site.

Carousel Slider is an AI-powered tool for creating stunning, SEO-friendly carousels. Easily showcase images, videos, logos, or content to boost engagement. Features include auto-generated sliders powered by AI, perfect for professional websites, e-commerce, and blogs.
GitHubGitHub
14
<p><strong>Create SEO friendly Image, Logo, Video, Post, WooCommerce Product Carousel, and Slider.</strong></p> <p>Carousel Slider is a touch-enabled WordPress plugin that lets you create a highly customizable,<br /> stylish responsive carousel slider. With Carousel Slider, you can create an image carousel using a media gallery or<br /> custom url, post carousel, video carousel.</p> <p><strong>If you like this plugin, please give us <a href="https://wordpress.org/support/plugin/carousel-slider/reviews/?rate=5#new-post" rel="ugc">5 star</a> to encourage for future improvement.</strong></p> <h4>Key Features List</h4> <ul> <li><strong>Support major website/page builder</strong>, including Gutenberg (WordPress core), Elementor, Visual Composer, SiteOrigin, Divi Builder</li> <li><strong>Multiple types carousel</strong>, images from media gallery, images from URL, videos from youtube and vimeo, posts, and WooCommerce products carousel slider</li> <li><strong>Hero slider</strong> with background image, title, description, call to action buttons and more</li> <li><strong>Posts carousel</strong>, support Specific posts, Post Categories, Post Tags, Posts per page, Date range query and ordering</li> <li><strong>Video carousel</strong>, support custom height and width (Currently only support video from Youtube and Vimeo)</li> <li><strong>WooCommerce Product carousel</strong>, support Product Categories, Product Tags, Specific Products, Featured Products, Recent Products, Sale Products, Best-Selling Products, Top Rated Products</li> <li>Options to hide/show product Title, Rating, Price, Cart Button, Sale Tag, Wishlist Button, Quick View button and options to change color for Title, Button Background, Button text</li> <li><strong>Fully responsive</strong>, configure the number of items to display for desktop, small desktop, tablet and mobile devices</li> <li><strong>Lightweight</strong>, only loads stuff when carousel is used</li> <li><strong>Navigation and pagination</strong>, choose what type of navigation is displayed for your carousel with unlimited colors option</li> <li><strong>Works great in touch devices</strong>, Touch and Grab enabled</li> <li>Supported in all major browsers</li> <li>CSS3 3D Acceleration</li> <li>Multiple carousel on same page</li> <li>Lazy load images</li> <li>Support image title, caption, link url</li> <li>and more options</li> </ul>
WordPress Plugin DirectoryWordPress Plugin Directory
1.14M