Logo Slider <= 5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lgx_tooltip_position' Parameter
medium
The Logo Slider – Logo Carousel, Client Logo Slider & Brand Showcase for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lgx_tooltip_position' parameter in all versions up to, and including, 5.5 due to insufficient input sanitization and output escaping. This makes it possible for a...
- CVSS:
- 6.4
- Affected:
- up to 5.5
- Fixed in:
- 5.5.4
- Disclosed:
- Jul 9, 2026
CVE-2026-13247 on NVD →
Logo Slider <= 4.9.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'logo-slider' Shortcode
medium
The Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image alt text in all versions up to, and including, 4.9.0 due to insufficient input sanitization and output escaping in the 'logo-slider' shortcode. This makes it possibl...
- CVSS:
- 6.4
- Affected:
- up to 4.9.0
- Fix:
- No patched version reported
- Disclosed:
- Mar 20, 2026
CVE-2026-0609 on NVD →
Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider Plugin [logo-slider-wp] <= 4.9.0 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LogicHunt Logo Slider logo-slider-wp allows Stored XSS.This issue affects Logo Slider: from n/a through <= 4.9.0.
- Affected:
- up to 4.9.0
- Fix:
- No patched version reported
- Disclosed:
- Jan 23, 2026
CVE-2026-24626 on NVD →
Logo Slider <= 5.5.3 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Logo Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will...
- CVSS:
- 6.4
- Affected:
- up to 5.5.3
- Fixed in:
- 5.5.4
- Disclosed:
- Jan 10, 2026
CVE-2026-24626 on NVD →
Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider Plugin [logo-slider-wp] < 4.9.0
unknown
[en] The Logo Slider WordPress plugin before 4.9.0 does not validate and escape some of its slider options before outputting them back in the dashboard, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
- Affected:
- up to 4.9.0
- Fixed in:
- 4.9.0
- Disclosed:
- Jan 2, 2026
CVE-2025-13153 on NVD →
Logo Slider <= 4.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level...
- CVSS:
- 6.4
- Affected:
- up to 4.8.0
- Fixed in:
- 4.9.0
- Disclosed:
- Dec 12, 2025
CVE-2025-13153 on NVD →
Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider Plugin [logo-slider-wp] < 4.6.0
unknown
[en] The Logo Slider WordPress plugin before 4.6.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
- Affected:
- up to 4.6.0
- Fixed in:
- 4.6.0
- Disclosed:
- Feb 24, 2025
CVE-2024-12308 on NVD →
Logo Slider <= 4.5.0 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Logo Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbit...
- CVSS:
- 4.4
- Affected:
- up to 4.5.0
- Fixed in:
- 4.6.0
- Disclosed:
- Feb 3, 2025
CVE-2024-12308 on NVD →
Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider Plugin [logo-slider-wp] < 4.5.0
unknown
[en] The Logo Slider WordPress plugin before 4.5.0 does not sanitise and escape some of its Logo Settings when outputing them in pages where the Logo Slider shortcode is embed, which could allow users with a role as low as Author to perform Cross-Site Scripting attacks.
- Affected:
- up to 4.5.0
- Fixed in:
- 4.5.0
- Disclosed:
- Nov 28, 2024
CVE-2024-10473 on NVD →
Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider Plugin [logo-slider-wp] < 4.5.0
unknown
[en] The Logo Slider WordPress plugin before 4.5.0 does not sanitise and escape some of its Logo and Slider settings, which could allow high privilege users such as Contributor to perform Stored Cross-Site Scripting
- Affected:
- up to 4.5.0
- Fixed in:
- 4.5.0
- Disclosed:
- Nov 28, 2024
CVE-2024-10896 on NVD →
Logo Slider <= 4.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Logo Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Brand Name" field in all versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbi...
- CVSS:
- 6.4
- Affected:
- up to 4.1.0
- Fixed in:
- 4.5.0
- Disclosed:
- Nov 7, 2024
CVE-2024-10896 on NVD →
Logo Slider <= 4.1.0 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Logo Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with author-level access a...
- CVSS:
- 6.4
- Affected:
- up to 4.1.0
- Fixed in:
- 4.5.0
- Disclosed:
- Nov 7, 2024
CVE-2024-10473 on NVD →
Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider Plugin [logo-slider-wp] < 4.1.0
unknown
[en] The Logo Slider WordPress plugin before 4.1.0 does not validate and escape some of its Slider Settings before outputting them back in attributes, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
- Affected:
- up to 4.1.0
- Fixed in:
- 4.1.0
- Disclosed:
- Oct 17, 2024
CVE-2024-5429 on NVD →
Logo Slider <= 4.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Brand Name field in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticat...
- CVSS:
- 6.4
- Affected:
- up to 4.0.0
- Fixed in:
- 4.1.0
- Disclosed:
- Sep 26, 2024
CVE-2024-5429 on NVD →
Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider Plugin [logo-slider-wp] < 4.0.0
unknown
[en] The Logo Slider WordPress plugin before 4.0.0 does not validate and escape some of its Slider Settings before outputting them back in attributes, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
- Affected:
- up to 4.0.0
- Fixed in:
- 4.0.0
- Disclosed:
- Jun 7, 2024
CVE-2024-3288 on NVD →
Logo Slider <= 3.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the header and subtitle parameter in all versions up to, and including, 3.9.9 due to insufficient input sanitization and output escaping. This makes it possible for...
- CVSS:
- 6.4
- Affected:
- up to 3.9.9
- Fixed in:
- 4.0.0
- Disclosed:
- May 17, 2024
CVE-2024-3288 on NVD →
Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider Plugin [logo-slider-wp] < 3.6.0
unknown
[en] The Logo Slider WordPress plugin before 3.6.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
- Affected:
- up to 3.6.0
- Fixed in:
- 3.6.0
- Disclosed:
- Feb 6, 2023
CVE-2022-4664 on NVD →
Logo Slider <= 3.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Logo Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via numerous shortcodes in versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping in the 'lgx_output_function_dep' function. This makes it possible for contributor-level attackers to inject arbitra...
- CVSS:
- 6.4
- Affected:
- up to 3.5.3
- Fixed in:
- 3.6.0
- Disclosed:
- Dec 16, 2022
CVE-2022-4664 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database