The SlideshowPluginSlideshowStylesheet::loadStylesheetByAJAX function in the Slideshow plugin 2.2.8 through 2.2.21 for Wordpress allows remote attackers to read arbitrary Wordpress option values.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/74453 | vdb entry third party advisory |
https://wordpress.org/plugins/slideshow-jquery-image-gallery/#developers | third party advisory release notes |
http://www.openwall.com/lists/oss-security/2015/05/02/12 | mailing list third party advisory patch |
https://github.com/Boonstra/Slideshow/commit/cac505e593cbe70a4d8af5b639f5385d4cc7aa04 | third party advisory patch |