plugin

Ays Slider Vulnerabilities

5 known security issues reported for the Ays Slider WordPress plugin. Most recent disclosed Mar 20, 2026.

2 high 3 medium

Running Ays Slider on your site? Check whether your installed version is affected.

Scan your site free

Image Slider by Ays- Responsive Slider and Carousel <= 2.7.1 - Unauthenticated Stored Cross-Site Scripting

high

The Image Slider by Ays- Responsive Slider and Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

CVSS:
7.2
Affected:
up to 2.7.1
Fixed in:
2.7.2
Disclosed:
Mar 20, 2026

CVE-2026-32494 on NVD →

Image Slider by Ays <= 2.7.1 - Missing Authorization

medium

The Image Slider by Ays plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.7.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.7.1
Fixed in:
2.7.2
Disclosed:
Feb 21, 2026

CVE-2026-32402 on NVD →

Image Slider by Ays- Responsive Slider and Carousel <= 2.7.0 - Cross-Site Request Forgery to Arbitrary Slider Deletion

medium

The Image Slider by Ays- Responsive Slider and Carousel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.0. This is due to missing or incorrect nonce validation on the bulk delete functionality. This makes it possible for unauthenticated attackers to delete arbi...

CVSS:
4.3
Affected:
up to 2.7.0
Fixed in:
2.7.1
Disclosed:
Dec 12, 2025

CVE-2025-14454 on NVD →

Image Slider by Ays- Responsive Slider and Carousel < 2.5.0 - SQL Injection

high

The get_sliders() function in the Image Slider by Ays- Responsive Slider and Carousel WordPress plugin before 2.5.0 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

CVSS:
8.8
Affected:
up to 2.5.0
Fixed in:
2.5.0
Disclosed:
Jun 29, 2021

CVE-2021-24463 on NVD →

Image Slider by Ays- Responsive Slider and Carousel <= 2.4.9 - Reflected Cross-Site Scripting

medium

The Image Slider by Ays- Responsive Slider and Carousel box plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 2.4.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbit...

CVSS:
6.1
Affected:
up to 2.4.9
Fixed in:
2.5.0
Disclosed:
Jun 29, 2021

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database