LBG Zoominoutslider - Reflected Cross Site Scripting (XSS) vulnerability
highReflected Cross Site Scripting (XSS) vulnerability
- CVSS:
- 7.1
- Affected:
- up to 5.4.5
- Fix:
- No patched version reported
- Disclosed:
- Feb 26, 2026
plugin
5 known security issues reported for the Lbg Zoominoutslider WordPress plugin. Most recent disclosed Feb 26, 2026.
Running Lbg Zoominoutslider on your site? Check whether your installed version is affected.
Scan your site freeReflected Cross Site Scripting (XSS) vulnerability
The Responsive Zoom In/Out Slider WordPress Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that e...
The LBG Zoominoutslider plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access...
The LBG Zoom In/Out Effect Slider for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in all known versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...
The Responsive Zoom In/Out Slider WordPress Plugin plugin for WordPress is vulnerable to Cross-Site Scripting via the 'add_banner.php' file due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free