The Full Screen (Page) Background Image Slideshow WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
History

Thu, 12 Jun 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Mohsinrasool
Mohsinrasool full Screen \(page\) Background Image Slideshow
Weaknesses CWE-79
CPEs cpe:2.3:a:mohsinrasool:full_screen_\(page\)_background_image_slideshow:*:*:*:*:*:wordpress:*:*
Vendors & Products Mohsinrasool
Mohsinrasool full Screen \(page\) Background Image Slideshow

Tue, 20 May 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 May 2025 20:15:00 +0000

Type Values Removed Values Added
Description The Full Screen (Page) Background Image Slideshow WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Title Full Screen (Page) Background Image Slideshow <= 1.1 - Admin+ Stored XSS
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-05-15T20:06:48.314Z

Updated: 2025-05-20T19:36:19.217Z

Reserved: 2024-11-14T18:01:52.242Z

Link: CVE-2024-11221

cve-icon Vulnrichment

Updated: 2025-05-19T20:36:36.288Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-15T20:15:34.437

Modified: 2025-06-12T15:11:36.310

Link: CVE-2024-11221

cve-icon Redhat

No data.