CVE-2021-24382
Estado: ModificadaMedia (5.4)—
The Smart Slider 3 Free and pro WordPress plugins before 3.5.0.9 did not sanitise the Project Name before outputting it back in the page, leading to a Stored Cross-Site Scripting issue. By default, only administrator users could access the affected functionality, limiting the exploitability of the vulnerability. However, some WordPress admins may allow lesser privileged users to access the plugin's functionality, in which case, privilege escalation could be performed.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 5.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.68%
- Percentil entre todas las CVEs puntuadas: 51
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-24382",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 3.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.3
}
]
},
"affected": [
{
"source": "contact@wpscan.com",
"affectedData": [
{
"vendor": "Nextend",
"product": "Smart Slider 3",
"versions": [
{
"status": "affected",
"version": "3.5.0.9",
"lessThan": "3.5.0.9",
"versionType": "custom"
}
]
},
{
"vendor": "Nextend",
"product": "Smart Slider 3",
"versions": [
{
"status": "affected",
"version": "3.5.0.9",
"lessThan": "3.5.0.9",
"versionType": "custom"
}
]
}
]
}
],
"published": "2021-06-14T14:15:09.117",
"references": [
{
"url": "https://smartslider.helpscoutdocs.com/article/1746-changelog",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "contact@wpscan.com"
},
{
"url": "https://wpscan.com/vulnerability/7b32a282-e51f-4ee5-b59f-5ba10e62a54d",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "contact@wpscan.com"
},
{
"url": "https://smartslider.helpscoutdocs.com/article/1746-changelog",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://wpscan.com/vulnerability/7b32a282-e51f-4ee5-b59f-5ba10e62a54d",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "contact@wpscan.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Smart Slider 3 Free and pro WordPress plugins before 3.5.0.9 did not sanitise the Project Name before outputting it back in the page, leading to a Stored Cross-Site Scripting issue. By default, only administrator users could access the affected functionality, limiting the exploitability of the vulnerability. However, some WordPress admins may allow lesser privileged users to access the plugin's functionality, in which case, privilege escalation could be performed."
},
{
"lang": "es",
"value": "Los plugins Smart Slider 3 Free y pro de WordPress versiones anteriores a 3.5.0.9, no saneaban el Nombre del Proyecto antes de devolverlo a la página, conllevando un problema de tipo Cross-Site Scripting almacenado. Por defecto, sólo los usuarios administradores podían acceder a la funcionalidad afectada, limitando la posibilidad de explotar la vulnerabilidad. Sin embargo, algunos administradores de WordPress pueden permitir a usuarios menos privilegiados acceder a la funcionalidad del plugin, en cuyo caso, una escalada de privilegios podría ser llevada a cabo"
}
],
"lastModified": "2026-06-17T03:39:56.083",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nextendweb:smart_slider:*:*:*:*:free:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "C8A259CF-BC57-45E4-BEE3-FE966D605A1F",
"versionEndExcluding": "3.5.0.9",
"versionStartIncluding": "3.0"
},
{
"criteria": "cpe:2.3:a:nextendweb:smart_slider:*:*:*:*:pro:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "6A757625-7C17-40D5-AF79-684450ECE021",
"versionEndExcluding": "3.5.0.9",
"versionStartIncluding": "3.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "contact@wpscan.com"
}