Input validation vulnerability in smart-slider-2 2.3.12

The Smart Slider 2 plugin for WordPress is vulnerable to a type of malicious attack. This attack, called Reflected Cross-Site Scripting, can be carried out if the user clicks on a link that has been created by an attacker. This vulnerability affects versions up to and including 2.3.11 due to the lack of input sanitization and output escaping that the plugin has. If the attack is successful, the attacker can inject scripts into the page that can be executed.

Detected in:

smart-slider-2 open vulnerable versions: >= * < 2.3.12

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.