plugin

Image Hover Effects Ultimate Vulnerabilities

17 known security issues reported for the Image Hover Effects Ultimate WordPress plugin. Most recent disclosed Nov 19, 2025.

1 critical 1 high 7 medium

Running Image Hover Effects Ultimate on your site? Check whether your installed version is affected.

Scan your site free

Multiple Plugins and Themes <= (Various Versions) - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via lightGallery JavaScript Library

medium

Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled lightGallery library (<= 2.8.3) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contrib...

CVSS:
6.4
Affected:
up to 9.10.5
Fix:
No patched version reported
Disclosed:
Nov 19, 2025

CVE-2025-5092 on NVD →

Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) [image-hover-effects-ultimate] >= 9.8.1 - <= 9.8.4

unknown

[en] The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several values that can be added to an Image Hover in versions 9.8.1 to 9.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web...

Affected:
9.8.1 – 9.8.4
Fixed in:
9.8.4
Disclosed:
Dec 13, 2022

CVE-2022-4207 on NVD →

Image Hover Effects Ultimate 9.8.1 - 9.8.4 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several values that can be added to an Image Hover in versions 9.8.1 to 9.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scri...

CVSS:
5.5
Affected:
9.8.1 – 9.8.4
Fixed in:
9.8.5
Disclosed:
Dec 11, 2022

CVE-2022-4207 on NVD →

Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) [image-hover-effects-ultimate] < 9.7.2

unknown

[en] Auth. WordPress Options Change vulnerability in Image Hover Effects Ultimate plugin <= 9.7.1 on WordPress.

Affected:
up to 9.7.2
Fixed in:
9.7.2
Disclosed:
Nov 18, 2022

CVE-2022-42459 on NVD →

Image Hover Effects Ultimate <= 9.7.1 - Authenticated (Admin+) Arbitrary Options Update

high

The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Arbitrary Options Update in versions up to, and including, 9.7.1. This is due to a lack of validation on the settings supplied to the post_oxi_settings() function. This makes it possible for authenticated attackers, with administrative level permiss...

CVSS:
7.2
Affected:
up to 9.7.1
Fixed in:
9.7.2
Disclosed:
Oct 25, 2022

CVE-2022-42459 on NVD →

Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) [image-hover-effects-ultimate] < 9.8.0

unknown

[en] The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title & Description values that can be added to an Image Hover in versions up to, and including, 9.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta...

Affected:
up to 9.8.0
Fixed in:
9.8.0
Disclosed:
Sep 23, 2022

CVE-2022-2937 on NVD →

Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) [image-hover-effects-ultimate] < 9.8.0

unknown

[en] The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Media Image URL value that can be added to an Image Hover in versions up to, and including, 9.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...

Affected:
up to 9.8.0
Fixed in:
9.8.0
Disclosed:
Sep 6, 2022

CVE-2022-2935 on NVD →

Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) [image-hover-effects-ultimate] < 9.8.0

unknown

[en] The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Video Link values that can be added to an Image Hover in versions up to, and including, 9.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inje...

Affected:
up to 9.8.0
Fixed in:
9.8.0
Disclosed:
Sep 6, 2022

CVE-2022-2936 on NVD →

Image Hover Effects Ultimate <= 9.7.3 - Authenticated Stored Cross-Site Scripting via Media URL

medium

The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Media Image URL value that can be added to an Image Hover in versions up to, and including, 9.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to i...

CVSS:
6.4
Affected:
up to 9.7.3
Fixed in:
9.8.0
Disclosed:
Aug 31, 2022

CVE-2022-2935 on NVD →

Image Hover Effects Ultimate <= 9.7.3 - Authenticated Stored Cross-Site Scripting via Video Link

medium

The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Video Link values that can be added to an Image Hover in versions up to, and including, 9.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject ar...

CVSS:
6.4
Affected:
up to 9.7.3
Fixed in:
9.8.0
Disclosed:
Aug 31, 2022

CVE-2022-2936 on NVD →

Image Hover Effects Ultimate <= 9.7.3 - Authenticated Stored Cross-Site Scripting via Title & Description

medium

The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title & Description values that can be added to an Image Hover in versions up to, and including, 9.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...

CVSS:
6.4
Affected:
up to 9.7.3
Fixed in:
9.8.0
Disclosed:
Aug 31, 2022

CVE-2022-2937 on NVD →

Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) [image-hover-effects-ultimate] < 9.7.2

unknown

[en] Authenticated (admin or higher user role) Reflected Cross-Site Scripting (XSS) vulnerability in Biplob Adhikari's Image Hover Effects Ultimate plugin <= 9.7.1 at WordPress.

Affected:
up to 9.7.2
Fixed in:
9.7.2
Disclosed:
May 20, 2022

CVE-2022-29424 on NVD →

Image Hover Effects Ultimate <= 9.7.1 - Reflected Cross-Site Scripting

medium

Authenticated (admin or higher user role) Reflected Cross-Site Scripting (XSS) vulnerability in Biplob Adhikari's Image Hover Effects Ultimate plugin <= 9.7.1 at WordPress. Please note that this is separate from CVE-2021-25031.

CVSS:
6.1
Affected:
up to 9.7.1
Fixed in:
9.7.2
Disclosed:
May 4, 2022

CVE-2022-29424 on NVD →

Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) [image-hover-effects-ultimate] < 9.7.1

unknown

[en] The Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) WordPress plugin before 9.7.1 does not escape the effects parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

Affected:
up to 9.7.1
Fixed in:
9.7.1
Disclosed:
Jan 24, 2022

CVE-2021-25031 on NVD →

Image Hover Effects Ultimate <= 9.7.0 - Reflected Cross-Site Scripting via effects

medium

The Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) WordPress plugin before 9.7.1 does not escape the effects parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 9.7.0
Fixed in:
9.7.1
Disclosed:
Dec 27, 2021

CVE-2021-25031 on NVD →

Image Hover Effects Ultimate <= 9.6.1 - Unauthenticated Arbitrary Options Update

critical

Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6.1) WordPress plugin.

CVSS:
9.8
Affected:
up to 9.6.1
Fixed in:
9.6.2
Disclosed:
Dec 15, 2021

CVE-2021-36888 on NVD →

Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) [image-hover-effects-ultimate] < 9.7.0

unknown

[en] Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6.1) WordPress plugin.

Affected:
up to 9.7.0
Fixed in:
9.7.0
Disclosed:
Dec 15, 2021

CVE-2021-36888 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database