High severity7.5NVD Advisory· Published Jun 8, 2017· Updated May 13, 2026
CVE-2015-3634
CVE-2015-3634
Description
The SlideshowPluginSlideshowStylesheet::loadStylesheetByAJAX function in the Slideshow plugin 2.2.8 through 2.2.21 for Wordpress allows remote attackers to read arbitrary Wordpress option values.
Affected products
14cpe:2.3:a:slideshow_project:slideshow:2.2.10:*:*:*:*:wordpress:*:*+ 13 more
- cpe:2.3:a:slideshow_project:slideshow:2.2.10:*:*:*:*:wordpress:*:*
- cpe:2.3:a:slideshow_project:slideshow:2.2.11:*:*:*:*:wordpress:*:*
- cpe:2.3:a:slideshow_project:slideshow:2.2.12:*:*:*:*:wordpress:*:*
- cpe:2.3:a:slideshow_project:slideshow:2.2.13:*:*:*:*:wordpress:*:*
- cpe:2.3:a:slideshow_project:slideshow:2.2.14:*:*:*:*:wordpress:*:*
- cpe:2.3:a:slideshow_project:slideshow:2.2.15:*:*:*:*:wordpress:*:*
- cpe:2.3:a:slideshow_project:slideshow:2.2.16:*:*:*:*:wordpress:*:*
- cpe:2.3:a:slideshow_project:slideshow:2.2.17:*:*:*:*:wordpress:*:*
- cpe:2.3:a:slideshow_project:slideshow:2.2.18:*:*:*:*:wordpress:*:*
- cpe:2.3:a:slideshow_project:slideshow:2.2.19:*:*:*:*:wordpress:*:*
- cpe:2.3:a:slideshow_project:slideshow:2.2.20:*:*:*:*:wordpress:*:*
- cpe:2.3:a:slideshow_project:slideshow:2.2.21:*:*:*:*:wordpress:*:*
- cpe:2.3:a:slideshow_project:slideshow:2.2.8:*:*:*:*:wordpress:*:*
- cpe:2.3:a:slideshow_project:slideshow:2.2.9:*:*:*:*:wordpress:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.openwall.com/lists/oss-security/2015/05/02/12nvdMailing ListPatchThird Party Advisory
- github.com/Boonstra/Slideshow/commit/cac505e593cbe70a4d8af5b639f5385d4cc7aa04nvdPatchThird Party Advisory
- www.securityfocus.com/bid/74453nvdThird Party AdvisoryVDB Entry
- wordpress.org/plugins/slideshow-jquery-image-gallery/nvdRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.