The Thumbnail carousel slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing nonce validation on the deleteselected function. This makes it possible for unauthenticated attackers to delete sliders in bulk via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Thumbnail_carousel_slider | I13websolution | 1.0 (including) | 1.0 (including) |