VYPR
High severity7.1NVD Advisory· Published Oct 5, 2024· Updated Apr 23, 2026

CVE-2024-47388

CVE-2024-47388

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iova.mihai SliceWP slicewp allows Reflected XSS.This issue affects SliceWP: from n/a through <= 1.1.18.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SliceWP plugin ≤1.1.18 suffers reflected XSS, allowing script injection via unsanitized input.

Vulnerability

Description SliceWP, a WordPress affiliate plugin, versions up to and including 1.1.18 contain a reflected cross-site scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation [1]. Reflected XSS occurs when an application echoes back malicious input without proper sanitization, allowing an attacker to craft a URL that embeds executable scripts.

Exploitation

Method To exploit this flaw, an attacker must convince a privileged user (e.g., a site administrator) to click a specially crafted link or visit a malicious page. This qualifies as “user interaction” required for successful exploitation [1]. The attack does not require prior authentication to the vulnerable site beyond the victim’s own session.

Impact

If exploited, the attacker can inject arbitrary JavaScript into the administrator’s browser session. This could be used to steal cookies, redirect visitors, deface the site, or deliver other HTML/script payloads [1]. The CVSS v3 base score is 7.1, reflecting moderate severity and a likelihood of mass exploitation [1].

Mitigation

Users must update the SliceWP plugin to version 1.1.19 or later, which contains a fix for the vulnerability. Those unable to update immediately should ask their hosting provider or web developer for assistance; Patchstack also provides a mitigation rule to block attacks until the patch is applied [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.