plugin

Master Slider Vulnerabilities

44 known security issues reported for the Master Slider WordPress plugin. Most recent disclosed Jun 19, 2026.

1 critical 2 high 17 medium

Running Master Slider on your site? Check whether your installed version is affected.

Scan your site free

Master Slider – Responsive Touch Slider <= 3.11.2 - Unauthenticated Stored Cross-Site Scripting

high

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.11.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execu...

CVSS:
7.2
Affected:
up to 3.11.2
Fix:
No patched version reported
Disclosed:
Jun 19, 2026

CVE-2026-56014 on NVD →

Master Slider – Responsive Touch Slider <= 3.10.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitr...

CVSS:
6.4
Affected:
up to 3.10.8
Fixed in:
3.10.9
Disclosed:
May 27, 2026

CVE-2026-48968 on NVD →

Master Slider <= 3.11.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Master Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages t...

CVSS:
6.4
Affected:
up to 3.11.1
Fixed in:
3.11.2
Disclosed:
Sep 22, 2025

CVE-2025-58025 on NVD →

Master Slider <= 3.10.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via masterslider_pb and ms_slide Shortcodes

medium

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's masterslider_pb and ms_slide shortcodes in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possib...

CVSS:
6.4
Affected:
up to 3.10.8
Fixed in:
3.10.9
Disclosed:
Jun 16, 2025

CVE-2025-5291 on NVD →

Master Slider &#8211; Responsive Touch Slider [master-slider] <= 3.10.8 (unfixed)

unknown

[en] Missing Authorization vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.10.8.

Affected:
up to 3.10.8
Fix:
No patched version reported
Disclosed:
May 19, 2025

CVE-2025-39412 on NVD →

Master Slider <= 3.11.1 - Missing Authorization

medium

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.11.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized actio...

CVSS:
4.3
Affected:
up to 3.11.1
Fixed in:
3.11.2
Disclosed:
Apr 17, 2025

CVE-2025-39412 on NVD →

Master Slider &#8211; Responsive Touch Slider [master-slider] <= 3.10.6 (unfixed)

unknown

[en] The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ms_layer shortcode in all versions up to, and including, 3.10.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentic...

Affected:
up to 3.10.6
Fix:
No patched version reported
Disclosed:
Mar 5, 2025

CVE-2024-13757 on NVD →

Master Slider &#8211; Responsive Touch Slider [master-slider] <= 3.10.7 (unfixed)

unknown

[en] The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ms_slider shortcode in all versions up to, and including, 3.10.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenti...

Affected:
up to 3.10.7
Fix:
No patched version reported
Disclosed:
Mar 5, 2025

CVE-2024-11731 on NVD →

Master Slider – Responsive Touch Slider <= 3.10.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via ms_layer Shortcode

medium

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ms_layer shortcode in all versions up to, and including, 3.10.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...

CVSS:
6.4
Affected:
up to 3.10.6
Fixed in:
3.10.7
Disclosed:
Mar 4, 2025

CVE-2024-13757 on NVD →

Master Slider – Responsive Touch Slider <= 3.10.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via ms_slider Shortcode

medium

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ms_slider shortcode in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...

CVSS:
6.4
Affected:
up to 3.10.7
Fixed in:
3.10.8
Disclosed:
Mar 4, 2025

CVE-2024-11731 on NVD →

Master Slider &#8211; Responsive Touch Slider [master-slider] < 3.10.5

unknown

[en] The Master Slider WordPress plugin before 3.10.5 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 3.10.5
Fixed in:
3.10.5
Disclosed:
Feb 19, 2025

CVE-2024-12173 on NVD →

Master Slider <= 3.10.0 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissio...

CVSS:
4.4
Affected:
up to 3.10.0
Fixed in:
3.10.5
Disclosed:
Jan 29, 2025

CVE-2024-12173 on NVD →

Master Slider &#8211; Responsive Touch Slider [master-slider] <= 3.9.10 (unfixed)

unknown

[en] During testing of the Master Slider WordPress plugin through 3.9.10, a CSRF vulnerability was found, which allows an unauthorized user to manipulate requests on behalf of the victim and thereby delete all of the sliders inside Master Slider WordPress plugin through 3.9.10.

Affected:
up to 3.9.10
Fix:
No patched version reported
Disclosed:
Jul 26, 2024

CVE-2024-6490 on NVD →

Master Slider <= 3.10.0 - Reflected Cross-Site Scripting

medium

The Master Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully...

CVSS:
6.1
Affected:
up to 3.10.0
Fixed in:
3.10.5
Disclosed:
Jun 20, 2024

CVE-2024-37222 on NVD →

Master Slider &#8211; Responsive Touch Slider [master-slider] < 3.10.5

unknown

[en] Cross Site Scripting (XSS) vulnerability in Averta Master Slider allows Reflected XSS.This issue affects Master Slider: from n/a through 3.10.0.

Affected:
up to 3.10.5
Fixed in:
3.10.5
Disclosed:
Jun 20, 2024

CVE-2024-37222 on NVD →

Master Slider &#8211; Responsive Touch Slider [master-slider] < 3.10.0

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.9.10.

Affected:
up to 3.10.0
Fixed in:
3.10.0
Disclosed:
Jun 19, 2024

CVE-2023-50900 on NVD →

Master Slider &#8211; Responsive Touch Slider [master-slider] < 3.10.0

unknown

[en] The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_layer' shortcode in all versions up to, and including, 3.9.10 due to insufficient input sanitization and output escaping on the 'css_id' user supplied attribute. This makes it possible...

Affected:
up to 3.10.0
Fixed in:
3.10.0
Disclosed:
Jun 18, 2024

CVE-2024-4375 on NVD →

Master Slider – Responsive Touch Slider <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via ms_layer Shortcode

medium

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_layer' shortcode in all versions up to, and including, 3.9.10 due to insufficient input sanitization and output escaping on the 'css_id' user supplied attribute. This makes it possible for...

CVSS:
6.4
Affected:
up to 3.9.10
Fixed in:
3.10.0
Disclosed:
Jun 17, 2024

CVE-2024-4375 on NVD →

Master Slider &#8211; Responsive Touch Slider [master-slider] < 3.9.10

unknown

[en] The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_slide' shortcode in all versions up to, and including, 3.9.9 due to insufficient input sanitization and output escaping on user supplied 'css_class' attribute. This makes it possible f...

Affected:
up to 3.9.10
Fixed in:
3.9.10
Disclosed:
Jun 1, 2024

CVE-2023-6382 on NVD →

Master Slider - Responsive Touch Slider <= 3.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_slide' shortcode in all versions up to, and including, 3.9.9 due to insufficient input sanitization and output escaping on user supplied 'css_class' attribute. This makes it possible for au...

CVSS:
6.4
Affected:
up to 3.9.9
Fixed in:
3.9.10
Disclosed:
May 31, 2024

CVE-2023-6382 on NVD →

Master Slider &#8211; Responsive Touch Slider [master-slider] < 3.9.10

unknown

[en] The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_slide_info' shortcode in all versions up to, and including, 3.9.9 due to insufficient input sanitization and output escaping on user supplied 'tag_name' attribute. This makes it possib...

Affected:
up to 3.9.10
Fixed in:
3.9.10
Disclosed:
May 21, 2024

CVE-2024-4470 on NVD →

Master Slider – Responsive Touch Slider <= 3.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_slide_info' shortcode in all versions up to, and including, 3.9.9 due to insufficient input sanitization and output escaping on user supplied 'tag_name' attribute. This makes it possible fo...

CVSS:
6.4
Affected:
up to 3.9.9
Fixed in:
3.9.10
Disclosed:
May 20, 2024

CVE-2024-4470 on NVD →

Master Slider &#8211; Responsive Touch Slider [master-slider] < 3.9.9

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Master Slider allows Stored XSS.This issue affects Master Slider: from n/a through 3.9.8.

Affected:
up to 3.9.9
Fixed in:
3.9.9
Disclosed:
Apr 18, 2024

CVE-2024-32580 on NVD →

Master Slider &#8211; Responsive Touch Slider [master-slider] < 3.9.7

unknown

[en] Deserialization of Untrusted Data vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.9.5.

Affected:
up to 3.9.7
Fixed in:
3.9.7
Disclosed:
Apr 18, 2024

CVE-2024-32600 on NVD →

Master Slider <= 3.9.5 - Unauthenticated PHP Object Injection

critical

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.9.5 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable plugin....

CVSS:
9.8
Affected:
up to 3.9.5
Fixed in:
3.9.7
Disclosed:
Apr 16, 2024

CVE-2024-32600 on NVD →

Master Slider – Responsive Touch Slider <= 3.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.9.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level acc...

CVSS:
6.4
Affected:
up to 3.9.8
Fixed in:
3.9.9
Disclosed:
Apr 16, 2024

CVE-2024-32580 on NVD →

Master Slider &#8211; Responsive Touch Slider [master-slider] < 3.9.10

unknown

[en] The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slides callback functionality in all versions up to, and including, 3.9.5. This makes it possible for authenticated attackers, with editor-level access, to inject arbitrary web scripts in pages tha...

Affected:
up to 3.9.10
Fixed in:
3.9.10
Disclosed:
Mar 2, 2024

CVE-2024-0611 on NVD →

Master Slider &#8211; Responsive Touch Slider [master-slider] < 3.10.0

unknown

[en] The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ms_slide shortcode in all versions up to, and including, 3.9.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica...

Affected:
up to 3.10.0
Fixed in:
3.10.0
Disclosed:
Mar 2, 2024

CVE-2024-1449 on NVD →

Master Slider &#8211; Responsive Touch Slider [master-slider] < 3.10.0

unknown

[en] The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.9.3. This is due to missing or incorrect nonce validation on the 'process_bulk_action' function. This makes it possible for unauthenticated attackers to duplicate or...

Affected:
up to 3.10.0
Fixed in:
3.10.0
Disclosed:
Mar 2, 2024

CVE-2023-6326 on NVD →

Master Slider – Responsive Touch Slider <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ms_slide shortcode in all versions up to, and including, 3.9.10 due to insufficient input sanitization and output escaping on the 'src' user supplied attributes. This makes it possible for auth...

CVSS:
6.4
Affected:
up to 3.9.10
Fixed in:
3.10.0
Disclosed:
Mar 1, 2024

CVE-2024-1449 on NVD →

Master Slider - Responsive Touch Slider <= 3.9.10 - Cross-Site Request Forgery via process_bulk_action

medium

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.9.10. This is due to missing or incorrect nonce validation on the 'process_bulk_action' function. This makes it possible for unauthenticated attackers to duplicate or dele...

CVSS:
5.4
Affected:
up to 3.9.10
Fixed in:
3.10.0
Disclosed:
Mar 1, 2024

CVE-2023-6326 on NVD →

Master Slider – Responsive Touch Slider <= 3.9.9 - Authenticated(Editor+) Stored Cross-Site Scripting via slider callback

medium

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slides callback functionality in all versions up to, and including, 3.9.9. This makes it possible for authenticated attackers, with editor-level access, to inject arbitrary web scripts in pages that wil...

CVSS:
4.4
Affected:
up to 3.9.9
Fixed in:
3.9.10
Disclosed:
Mar 1, 2024

CVE-2024-0611 on NVD →

Master Slider &#8211; Responsive Touch Slider [master-slider] < 3.7.5

unknown

[en] The Master Slider plugin 3.2.7 and 3.5.1 for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings value on Callback.

Affected:
up to 3.7.5
Fixed in:
3.7.5
Disclosed:
Dec 23, 2018

CVE-2018-20368 on NVD →

Master Slider <= 3.7.0 - Authenticated Stored Cross-Site Scripting

medium

The Master Slider plugin for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings value on Callback.

CVSS:
5.4
Affected:
up to 3.7.0
Fixed in:
3.7.5
Disclosed:
Nov 14, 2018

CVE-2018-20368 on NVD →

Master Slider <= 2.7.1 - Cross-Site Scripting

medium

The Master Slider plugin for WordPress is vulnerable to Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user access...

CVSS:
6.1
Affected:
up to 2.8.0
Fixed in:
2.8.0
Disclosed:
Jul 16, 2016

Master Slider &#8211; Responsive Touch Slider [master-slider] < 2.8.0

unknown

The Master Slider plugin for WordPress is vulnerable to Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user access...

Affected:
up to 2.8.0
Fixed in:
2.8.0
Disclosed:
Jul 16, 2016

Master Slider &#8211; Responsive Touch Slider [master-slider] < 2.8.0

unknown

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Upgrade this plugin.

Affected:
up to 2.8.0
Fixed in:
2.8.0
Disclosed:
Jul 13, 2016

Master Slider - Responsive Touch Slider <= 2.5.1 - Authenticated Blind SQL Injection

high

The Master Slider - Responsive Touch Slider plugin for WordPress is vulnerable to blind SQL Injection via the ‘orderby’ parameter in versions up to, and including, 2.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for a...

CVSS:
8.8
Affected:
up to 2.5.2
Fixed in:
2.5.2
Disclosed:
Aug 20, 2015

Master Slider &#8211; Responsive Touch Slider [master-slider] < 2.5.2

unknown

The Master Slider - Responsive Touch Slider plugin for WordPress is vulnerable to blind SQL Injection via the ‘orderby’ parameter in versions up to, and including, 2.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for a...

Affected:
up to 2.5.2
Fixed in:
2.5.2
Disclosed:
Aug 20, 2015

Master Slider &#8211; Responsive Touch Slider [master-slider] < 2.5.2

unknown

Because of this vulnerability, authenticated users can execute arbitrary SQL commands. Upgrade this plugin.

Affected:
up to 2.5.2
Fixed in:
2.5.2
Disclosed:
Aug 20, 2015

Master Slider &#8211; Responsive Touch Slider [master-slider] <= 3.10.7 (unfixed)

unknown
Affected:
up to 3.10.7
Fix:
No patched version reported

Master Slider &#8211; Responsive Touch Slider [master-slider] < 3.10.9

unknown
Affected:
up to 3.10.9
Fixed in:
3.10.9

CVE-2025-5291 on NVD →

Master Slider &#8211; Responsive Touch Slider [master-slider] < 2.5.2

unknown

The Master Slider &ndash; Responsive Touch Slider WordPress plugin was affected by an Authenticated Blind SQL Injection security vulnerability.

Affected:
up to 2.5.2
Fixed in:
2.5.2

Master Slider &#8211; Responsive Touch Slider [master-slider] < 2.8.0

unknown

The Master Slider &ndash; Responsive Touch Slider WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability. In order to exploit this issue, the attacker has to lure/force a logged on WordPress Administrator into opening a malicious website/page.

Affected:
up to 2.8.0
Fixed in:
2.8.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database