plugin

Image Slider Widget Vulnerabilities

14 known security issues reported for the Image Slider Widget WordPress plugin. Most recent disclosed Apr 24, 2024.

1 critical 2 high 3 medium

Running Image Slider Widget on your site? Check whether your installed version is affected.

Scan your site free

Image Slider [image-slider-widget] < 1.1.127

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Image Slider Widget allows Stored XSS.This issue affects Image Slider Widget: from n/a through 1.1.125.

Affected:
up to 1.1.127
Fixed in:
1.1.127
Disclosed:
Apr 24, 2024

CVE-2024-32707 on NVD →

Image Slider <= 1.1.125 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The Image Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 1.1.125 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web s...

CVSS:
4.4
Affected:
up to 1.1.125
Fixed in:
1.1.127
Disclosed:
Apr 22, 2024

CVE-2024-32707 on NVD →

Image Slider [image-slider-widget] < 1.1.123

unknown

[en] The WordPress plugin Image Slider is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.1.121 due to failure to properly check for the existence of a nonce in the function ewic_duplicate_slider. This make it possible for unauthenticated attackers to duplicate existing posts or pages grante...

Affected:
up to 1.1.123
Fixed in:
1.1.123
Disclosed:
Jul 18, 2022

CVE-2022-2223 on NVD →

Image Slider <= 1.1.119 - Subscriber+ SQL Injection

high

The plugin Image Slider is vulnerable to SQL Injection via the post parameter in the function ewic_duplicate_slider in versions up to, and including 1.1.119 due to insufficient sanitization before using it in an unprepared SQL query. This make it possible for subscribers to append additional SQL queries into already ex...

CVSS:
8.8
Affected:
up to 1.1.119
Fixed in:
1.1.121
Disclosed:
May 24, 2022

Image Slider <= 1.1.121 - Cross-Site Request Forgery to Post Duplication

medium

The WordPress plugin Image Slider is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.1.121 due to failure to properly check for the existence of a nonce in the function ewic_duplicate_slider. This make it possible for unauthenticated attackers to duplicate existing posts or pages granted the...

CVSS:
5.4
Affected:
up to 1.1.121
Fixed in:
1.1.123
Disclosed:
May 24, 2022

CVE-2022-2223 on NVD →

Image Slider [image-slider-widget] < 1.1.121

unknown

The plugin Image Slider is vulnerable to SQL Injection via the post parameter in the function ewic_duplicate_slider in versions up to, and including 1.1.119 due to insufficient sanitization before using it in an unprepared SQL query. This make it possible for subscribers to append additional SQL queries into already ex...

Affected:
up to 1.1.121
Fixed in:
1.1.121
Disclosed:
May 24, 2022

Image Slider <= 1.1.95 - SQL Injection

critical

The Image Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'image-slider-widget/trunk/inc/functions/ewic-functions.php' file in the '$file' and ' $post_id' parameters in versions up to, and including, 1.1.95 due to insufficient escaping on the user supplied parameters and lack of sufficient pr...

CVSS:
9.8
Affected:
up to 1.1.95
Fixed in:
1.1.97
Disclosed:
Jan 28, 2018

Image Slider [image-slider-widget] < 1.1.97

unknown

The Image Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'image-slider-widget/trunk/inc/functions/ewic-functions.php' file in the '$file' and ' $post_id' parameters in versions up to, and including, 1.1.95 due to insufficient escaping on the user supplied parameters and lack of sufficient pr...

Affected:
up to 1.1.97
Fixed in:
1.1.97
Disclosed:
Jan 28, 2018

Image Slider < 1.1.90 - Arbitrary File Deletion

high

The Image Slider plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.1.89. This is due to allowing any user to edit 'Sliders'. This makes it possible for authenticated attackers with account level to create/edit posts to delete any files found in the plugin.

CVSS:
8.1
Affected:
up to 1.1.90
Fixed in:
1.1.90
Disclosed:
Dec 23, 2016

Image Slider [image-slider-widget] < 1.1.90

unknown

The Image Slider plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.1.89. This is due to allowing any user to edit 'Sliders'. This makes it possible for authenticated attackers with account level to create/edit posts to delete any files found in the plugin.

Affected:
up to 1.1.90
Fixed in:
1.1.90
Disclosed:
Dec 23, 2016

Image Slider [image-slider-widget] < 1.1.7

unknown

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Update the plugin.

Affected:
up to 1.1.7
Fixed in:
1.1.7
Disclosed:
May 14, 2015

PrettyPhoto Library (Multiple Plugins and Themes) <= 3.1.4 - DOM Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.

CVSS:
6.1
Affected:
up to 1.1.7
Fixed in:
1.1.7
Disclosed:
Aug 1, 2014

CVE-2013-6837 on NVD →

Image Slider [image-slider-widget] < 1.1.7

unknown

[en] Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.

Affected:
up to 1.1.7
Fixed in:
1.1.7
Disclosed:
Dec 19, 2013

CVE-2013-6837 on NVD →

Image Slider [image-slider-widget] < 1.1.90

unknown

The Image Slider WordPress plugin was affected by an Authenticated Arbitrary File Deletion security vulnerability.

Affected:
up to 1.1.90
Fixed in:
1.1.90

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database