Page 2 of 6 results (0.032 seconds)

CVSS: 4.3EPSS: %CPEs: 1EXPL: 0

The Carousel Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_optin_optout() function hooked via 'admin_init' in versions up to, and including, 2.2.2. This makes it possible for unauthenticated attackers to opt in and opt out of tracking for the plugin. • CWE-862: Missing Authorization •