CVE-2024-6490

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
26/07/2024
Last modified:
27/05/2025

Description

During testing of the Master Slider WordPress plugin through 3.9.10, a CSRF vulnerability was found, which allows an unauthorized user to manipulate requests on behalf of the victim and thereby delete all of the sliders inside Master Slider WordPress plugin through 3.9.10.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:averta:master_slider:*:*:*:*:*:wordpress:*:* 3.10.0 (excluding)