Vendorsi13websolutionthumbnail_slider_with_lightbox1.0
Vulnerabilities

i13websolution I Thirteen Web Solution Thumbnail Slider With Lightbox 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2023-5820
The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the addedit functionality. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Published 2023-10-27 · Modified
9.6EPSS 0.003
CVE-2023-5621
Thumbnail Slider With Lightbox <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via Image Title
Published 2023-10-18 · Modified
4.8EPSS 0.004