plugin

Lbg Zoominoutslider Vulnerabilities

5 known security issues reported for the Lbg Zoominoutslider WordPress plugin. Most recent disclosed Feb 26, 2026.

1 high 4 medium

Running Lbg Zoominoutslider on your site? Check whether your installed version is affected.

Scan your site free

LBG Zoominoutslider - Reflected Cross Site Scripting (XSS) vulnerability

high

Reflected Cross Site Scripting (XSS) vulnerability

CVSS:
7.1
Affected:
up to 5.4.5
Fix:
No patched version reported
Disclosed:
Feb 26, 2026

Responsive Zoom In/Out Slider WordPress Plugin <= 5.4.5 - Reflected Cross-Site Scripting

medium

The Responsive Zoom In/Out Slider WordPress Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that e...

CVSS:
6.1
Affected:
up to 5.4.5
Fix:
No patched version reported
Disclosed:
Feb 26, 2026

CVE-2026-28103 on NVD →

LBG Zoominoutslider <= 5.4.4 - Authenticated (Contributor+) SQL Injection

medium

The LBG Zoominoutslider plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access...

CVSS:
6.5
Affected:
up to 5.4.4
Fixed in:
5.4.5
Disclosed:
Sep 28, 2025

CVE-2025-68056 on NVD →

Responsive Zoom In/Out Slider WordPress Plugin (Unknown Versions) - Cross-Site Scripting

medium

The LBG Zoom In/Out Effect Slider for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in all known versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...

CVSS:
6.1
Affected:
up to *
Fix:
No patched version reported
Disclosed:
Nov 4, 2013

Responsive Zoom In/Out Slider WordPress Plugin (Unknown Versions) - Cross-Site Scripting

medium

The Responsive Zoom In/Out Slider WordPress Plugin plugin for WordPress is vulnerable to Cross-Site Scripting via the 'add_banner.php' file due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to *
Fix:
No patched version reported
Disclosed:
Sep 24, 2013

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database