CVE-2024-3027

The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the upload function in all versions up to, and including, 3.5.1.22. This makes it possible for authenticated attackers, with contributor-level access and above, to upload files, including SVG files, which can be used to conduct stored cross-site scripting attacks.
Configurations

No configuration.

History

08 Apr 2026, 18:21

Type Values Removed Values Added
CWE CWE-285

21 Nov 2024, 09:28

Type Values Removed Values Added
References () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3069057%40smart-slider-3&old=2996377%40smart-slider-3&sfp_email=&sfph_mail= - () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3069057%40smart-slider-3&old=2996377%40smart-slider-3&sfp_email=&sfph_mail= -
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/915f464f-449d-4ad2-9f43-6ce5d93ccb05?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/915f464f-449d-4ad2-9f43-6ce5d93ccb05?source=cve -

13 Apr 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-13 02:15

Updated : 2026-04-08 18:21


NVD link : CVE-2024-3027

Mitre link : CVE-2024-3027

CVE.ORG link : CVE-2024-3027


JSON object : View

Products Affected

No product.

CWE
CWE-285

Improper Authorization