Vendorsi13websolutionvideo_carousel_slider_with_lightboxall versions
Vulnerabilities

i13websolution Video Carousel Slider With Lightbox

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2019-25212
video carousel slider with lightbox <= 1.0.6 - Authenticated (Admin+) SQL Injection
Published 2024-09-11 · Modified
7.2EPSS 0.005
CVE-2023-32797
WordPress video carousel slider with lightbox Plugin <= 1.0.22 is vulnerable to Cross Site Scripting (XSS)
Published 2023-08-25 · Modified
7.1EPSS 0.004
CVE-2023-2710
video carousel slider with lightbox <= 1.0.22 - Reflected Cross-Site Scripting
Published 2023-05-16 · Modified
6.1EPSS 0.006
CVE-2023-5945
The video carousel slider with lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the responsive_video_gallery_with_lightbox_video_management_func() function. This makes it possible for unauthenticated attackers to delete videos hosted from the video slider via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Published 2023-11-03 · Modified
5.4EPSS 0.003