The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
2025-03-25T06:15:38.147
2025-04-01T16:45:55.157
Analyzed
CVSSv3.1: 6.1 (MEDIUM)