CVE-2024-4375

Master Slider – Responsive Touch Slider <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via ms_layer Shortcode

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_layer' shortcode in all versions up to, and including, 3.9.10 due to insufficient input sanitization and output escaping on the 'css_id' user supplied attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 70,392 live websites that are affected by CVE-2024-4375.

Test my site




Affected Software

Product  Master Slider
Category Wordpress Plugins
Vulnerable Domains70,392 live websites (100.00% of Master Slider install base)
Vulnerable Versions
  • from 0 through 3.9.10
Vulnerable Versions Count125 versions ( 100.00% of all versions)



Details

  • Published - Jun 18, 2024
  • Updated - Aug 1, 2024

Credits

  • Krzysztof Zając (finder)

CVE-2024-4375 usage by Country

United States23,091 websites



Germany9,192 websites
France4,802 websites
GB2,708 websites
Japan2,060 websites
Italy2,039 websites
Netherlands1,971 websites
Russia1,892 websites
Spain1,848 websites
Poland1,690 websites

CVE-2024-4375 usage by TLD

.com30,967 websites
.de4,570 websites
.org2,739 websites
.co.uk1,980 websites
.nl1,808 websites
.it1,681 websites
.fr1,584 websites
.com.br1,564 websites
.ru1,521 websites
.net1,411 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-4375

Top websites that are affected by CVE-2024-4375. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.org United States**,***
*********************.com United States**,***
*************.jp Japan**,***
********.tv United States**,***
*******.org United States**,***
*****.com United States**,***
*************.com United States**,***
***************.org United States**,***
******.org United States**,***
****.org United States**,***
See full domain list

FAQ

A total of 70,392 websites have been identified as vulnerable to CVE-2024-4375, discovered through global website indexing conducted by WebTechSurvey.
Master Slider is susceptible to CVE-2024-4375 vulnerability.
Master Slider versions before, and including, 3.9.10 are vulnerable to CVE-2024-4375.