<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 06:28:58 +0000</lastBuildDate>
    <item>
      <title>CVE-2021-24382 — Smart Slider 3 &lt; 3.5.0.9 - Authenticated Stored Cross-Site Scripting (XSS)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2021-24382</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Nextend Smart Slider 3&lt;/p&gt;
&lt;p&gt;The Smart Slider 3 Free and pro WordPress plugins before 3.5.0.9 did not sanitise the Project Name before outputting it back in the page, leading to a Stored Cross-Site Scripting issue. By default, only administrator users could access the affected functionality, limiting the exploitability of the vulnerability. However, some WordPress admins may allow lesser privileged users to access the plugin&amp;#39;s functionality, in which case, privilege escalation could be performed.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Nextend Smart Slider 3&lt;/p&gt;
&lt;p&gt;The Smart Slider 3 Free and pro WordPress plugins before 3.5.0.9 did not sanitise the Project Name before outputting it back in the page, leading to a Stored Cross-Site Scripting issue. By default, only administrator users could access the affected functionality, limiting the exploitability of the vulnerability. However, some WordPress admins may allow lesser privileged users to access the plugin&amp;#39;s functionality, in which case, privilege escalation could be performed.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2021-24382</guid>
    </item>
  </channel>
</rss>
