Infornweb Logo Showcase with Slick Slider
cpe:2.3:a:infornweb:logo_showcase_with_slick_slider:*:*:*:*:wordpress:*:*
- < 2.0.1
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Logo Showcase with Slick Slider WordPress plugin, affecting versions prior to 2.0.1. The vulnerability arises because the plugin's AJAX action 'lswss_save_attachment_data' lacks proper CSRF protection. This flaw allows attackers to manipulate a logged-in user with high privileges into changing the title, description, alt text, and URL of any uploaded media.
Exploitation of this vulnerability allows for unauthorized modification of media metadata, including titles, descriptions, alt text, and URLs, potentially leading to misinformation or misuse of media assets.
To reproduce this vulnerability, send a POST request to the WordPress AJAX endpoint with the action 'lswss_save_attachment_data'. Include the 'attachment_id' of the media to be modified and the 'form_data' parameter containing the new title, description, alt text, and URL. This request can be made using JavaScript, for example with jQuery's AJAX methods.
Users are advised to update the Logo Showcase with Slick Slider WordPress plugin to version 2.0.1 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.