CVE-2021-24742
Logo Slider and Showcase < 1.3.37 - Editor Plugin's Settings Update
The Logo Slider and Showcase WordPress plugin before 1.3.37 allows Editor users to update the plugin's settings via the rtWLSSettings AJAX action because it uses a nonce for authorisation instead of a capability check.
Affected products
Unknown · Logo Slider and ShowcaseWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →