← WordPress Vulnerabilities
WordPress security by component

Comparison Slider

Comparison Slider is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published May 30, 2024; the highest CVE/CNA score is 6.4.

Plugin slug: comparison-slider

CVE-2024-4427: Comparison Slider: A security weakness

Comparison Slider is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedMay 30, 2024
Safe version guidanceSee mitigation notes
Safe version
May 30, 2024 CVE-2024-4427
Comparison Slider: A security weakness
Comparison Slider is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
May 30, 2024 CVE-2024-4426
Comparison Slider: Cross-site request forgery
Comparison Slider is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
May 30, 2024 CVE-2024-4422
Comparison Slider: Cross-site scripting
Comparison Slider is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4