Logo Slider <= 3.7.3 - Unauthenticated Arbitrary Shortcode Execution
high
The The Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.7.3. This is due to the software allowing users to execute an action that does not properly validate a value before ru...
- CVSS:
- 7.3
- Affected:
- up to 3.7.3
- Fixed in:
- 3.7.4
- Disclosed:
- Mar 17, 2025
CVE-2025-2262 on NVD →
Logo Slider <= 3.7.0 - Cross-Site Request Forgery
medium
The Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.7.0. This is due to missing or incorrect nonce validation on the save_shortcode_pref function. This makes it possible for una...
- CVSS:
- 4.3
- Affected:
- up to 3.7.0
- Fixed in:
- 3.7.1
- Disclosed:
- Oct 3, 2024
CVE-2024-9233 on NVD →
Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation [gs-logo-slider] < 3.6.9
unknown
[en] The Logo Slider WordPress plugin before 3.6.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 3.6.9
- Fixed in:
- 3.6.9
- Disclosed:
- Sep 11, 2024
CVE-2024-7716 on NVD →
Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation <= 3.6.8 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...
- CVSS:
- 4.4
- Affected:
- up to 3.6.8
- Fixed in:
- 3.6.9
- Disclosed:
- Aug 20, 2024
CVE-2024-7716 on NVD →
Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation [gs-logo-slider] < 3.5.2
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in GS Plugins Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation.This issue affects Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation: from n/a through 3.5.1.
- Affected:
- up to 3.5.2
- Fixed in:
- 3.5.2
- Disclosed:
- Feb 29, 2024
CVE-2023-51530 on NVD →
GS Logo Slider <= 3.5.1 - Cross-Site Request Forgery
medium
The Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.5.1. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated...
- CVSS:
- 4.3
- Affected:
- up to 3.5.1
- Fixed in:
- 3.5.2
- Disclosed:
- Dec 27, 2023
CVE-2023-51530 on NVD →
Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation [gs-logo-slider] < 3.3.8
unknown
[en] The GS Logo Slider WordPress plugin before 3.3.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as a...
- Affected:
- up to 3.3.8
- Fixed in:
- 3.3.8
- Disclosed:
- Jan 23, 2023
CVE-2022-4624 on NVD →
GS Logo Slider – Ticker, Grid, List, Table & Filter Views <= 3.3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The GS Logo Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 3.3.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level and a...
- CVSS:
- 6.4
- Affected:
- up to 3.3.7
- Fixed in:
- 3.3.8
- Disclosed:
- Dec 29, 2022
CVE-2022-4624 on NVD →
Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation [gs-logo-slider] < 3.4.3
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 3.4.3
- Fixed in:
- 3.4.3
CVE-2022-47150 on NVD →
Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation [gs-logo-slider] < 3.7.1
unknown
- Affected:
- up to 3.7.1
- Fixed in:
- 3.7.1
CVE-2024-9233 on NVD →
Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation [gs-logo-slider] < 3.7.4
unknown
- Affected:
- up to 3.7.4
- Fixed in:
- 3.7.4
CVE-2025-2262 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database