Vendorsi13websolutionteam_circle_image_slider_with_lightboxall versions
Vulnerabilities

i13websolution Team Circle Image Slider With Lightbox

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2022-0648
Team Circle Image Slider With Lightbox < 1.0.16 - Reflected Cross-Site Scripting
Published 2022-03-14 · Modified
6.1EPSS 0.008
CVE-2023-2604
Team Circle Image Slider With Lightbox <= 1.0.17 - Reflected Cross-Site Scripting
Published 2023-06-09 · Modified
6.1EPSS 0.004
CVE-2015-10130
The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the circle_thumbnail_slider_with_lightbox_image_management_func() function. This makes it possible for unauthenticated attackers to edit image data which can be used to inject malicious JavaScript, along with deleting images, and uploading malicious files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Published 2024-03-13 · Analyzed
5.3EPSS 0.002