The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_layer' shortcode in all versions up to, and including, 3.9.10 due to insufficient input sanitization and output escaping on the 'css_id' user supplied attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 70,392 live websites that are affected by CVE-2024-4375.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 70,392 live websites (100.00% of Master Slider install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 125 versions ( 100.00% of all versions) |
![]() | 23,091 websites |
![]() | 9,192 websites |
![]() | 4,802 websites |
![]() | 2,708 websites |
![]() | 2,060 websites |
![]() | 2,039 websites |
![]() | 1,971 websites |
![]() | 1,892 websites |
![]() | 1,848 websites |
![]() | 1,690 websites |
.com | 30,967 websites |
.de | 4,570 websites |
.org | 2,739 websites |
.co.uk | 1,980 websites |
.nl | 1,808 websites |
.it | 1,681 websites |
.fr | 1,584 websites |
.com.br | 1,564 websites |
.ru | 1,521 websites |
.net | 1,411 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*********.org | ![]() | **,*** | |
*********************.com | ![]() | **,*** | |
*************.jp | ![]() | **,*** | |
********.tv | ![]() | **,*** | |
*******.org | ![]() | **,*** | |
*****.com | ![]() | **,*** | |
*************.com | ![]() | **,*** | |
***************.org | ![]() | **,*** | |
******.org | ![]() | **,*** | |
****.org | ![]() | **,*** |
FAQ