CyberRota Analysis
AI-GeneratedThe Slick Slider WordPress plugin prior to version 0.5.3 is vulnerable to Stored Cross-Site Scripting due to inadequate sanitization of shortcode attribute values, allowing users with Contributor roles and higher to inject malicious scripts. This could lead to unauthorized script execution when other users view the affected posts, potentially compromising user data and site integrity. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Slick Slider WordPress plugin before 0.5.3 does not sanitize and escape a shortcode attribute value before outputting it in an HTML attribute, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute when a user views the affected post.