Master Slider – Responsive Touch Slider <= 3.11.2 - Unauthenticated Stored Cross-Site Scripting
high
The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.11.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execu...
- CVSS:
- 7.2
- Affected:
- up to 3.11.2
- Fix:
- No patched version reported
- Disclosed:
- Jun 19, 2026
CVE-2026-56014 on NVD →
Master Slider – Responsive Touch Slider <= 3.10.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitr...
- CVSS:
- 6.4
- Affected:
- up to 3.10.8
- Fixed in:
- 3.10.9
- Disclosed:
- May 27, 2026
CVE-2026-48968 on NVD →
Master Slider <= 3.11.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Master Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages t...
- CVSS:
- 6.4
- Affected:
- up to 3.11.1
- Fixed in:
- 3.11.2
- Disclosed:
- Sep 22, 2025
CVE-2025-58025 on NVD →
Master Slider <= 3.10.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via masterslider_pb and ms_slide Shortcodes
medium
The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's masterslider_pb and ms_slide shortcodes in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possib...
- CVSS:
- 6.4
- Affected:
- up to 3.10.8
- Fixed in:
- 3.10.9
- Disclosed:
- Jun 16, 2025
CVE-2025-5291 on NVD →
Master Slider – Responsive Touch Slider [master-slider] <= 3.10.8 (unfixed)
unknown
[en] Missing Authorization vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.10.8.
- Affected:
- up to 3.10.8
- Fix:
- No patched version reported
- Disclosed:
- May 19, 2025
CVE-2025-39412 on NVD →
Master Slider <= 3.11.1 - Missing Authorization
medium
The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.11.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized actio...
- CVSS:
- 4.3
- Affected:
- up to 3.11.1
- Fixed in:
- 3.11.2
- Disclosed:
- Apr 17, 2025
CVE-2025-39412 on NVD →
Master Slider – Responsive Touch Slider [master-slider] <= 3.10.6 (unfixed)
unknown
[en] The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ms_layer shortcode in all versions up to, and including, 3.10.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentic...
- Affected:
- up to 3.10.6
- Fix:
- No patched version reported
- Disclosed:
- Mar 5, 2025
CVE-2024-13757 on NVD →
Master Slider – Responsive Touch Slider [master-slider] <= 3.10.7 (unfixed)
unknown
[en] The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ms_slider shortcode in all versions up to, and including, 3.10.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenti...
- Affected:
- up to 3.10.7
- Fix:
- No patched version reported
- Disclosed:
- Mar 5, 2025
CVE-2024-11731 on NVD →
Master Slider – Responsive Touch Slider <= 3.10.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via ms_layer Shortcode
medium
The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ms_layer shortcode in all versions up to, and including, 3.10.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...
- CVSS:
- 6.4
- Affected:
- up to 3.10.6
- Fixed in:
- 3.10.7
- Disclosed:
- Mar 4, 2025
CVE-2024-13757 on NVD →
Master Slider – Responsive Touch Slider <= 3.10.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via ms_slider Shortcode
medium
The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ms_slider shortcode in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...
- CVSS:
- 6.4
- Affected:
- up to 3.10.7
- Fixed in:
- 3.10.8
- Disclosed:
- Mar 4, 2025
CVE-2024-11731 on NVD →
Master Slider – Responsive Touch Slider [master-slider] < 3.10.5
unknown
[en] The Master Slider WordPress plugin before 3.10.5 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 3.10.5
- Fixed in:
- 3.10.5
- Disclosed:
- Feb 19, 2025
CVE-2024-12173 on NVD →
Master Slider <= 3.10.0 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissio...
- CVSS:
- 4.4
- Affected:
- up to 3.10.0
- Fixed in:
- 3.10.5
- Disclosed:
- Jan 29, 2025
CVE-2024-12173 on NVD →
Master Slider – Responsive Touch Slider [master-slider] <= 3.9.10 (unfixed)
unknown
[en] During testing of the Master Slider WordPress plugin through 3.9.10, a CSRF vulnerability was found, which allows an unauthorized user to manipulate requests on behalf of the victim and thereby delete all of the sliders inside Master Slider WordPress plugin through 3.9.10.
- Affected:
- up to 3.9.10
- Fix:
- No patched version reported
- Disclosed:
- Jul 26, 2024
CVE-2024-6490 on NVD →
Master Slider <= 3.10.0 - Reflected Cross-Site Scripting
medium
The Master Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully...
- CVSS:
- 6.1
- Affected:
- up to 3.10.0
- Fixed in:
- 3.10.5
- Disclosed:
- Jun 20, 2024
CVE-2024-37222 on NVD →
Master Slider – Responsive Touch Slider [master-slider] < 3.10.5
unknown
[en] Cross Site Scripting (XSS) vulnerability in Averta Master Slider allows Reflected XSS.This issue affects Master Slider: from n/a through 3.10.0.
- Affected:
- up to 3.10.5
- Fixed in:
- 3.10.5
- Disclosed:
- Jun 20, 2024
CVE-2024-37222 on NVD →
Master Slider – Responsive Touch Slider [master-slider] < 3.10.0
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.9.10.
- Affected:
- up to 3.10.0
- Fixed in:
- 3.10.0
- Disclosed:
- Jun 19, 2024
CVE-2023-50900 on NVD →
Master Slider – Responsive Touch Slider [master-slider] < 3.10.0
unknown
[en] The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_layer' shortcode in all versions up to, and including, 3.9.10 due to insufficient input sanitization and output escaping on the 'css_id' user supplied attribute. This makes it possible...
- Affected:
- up to 3.10.0
- Fixed in:
- 3.10.0
- Disclosed:
- Jun 18, 2024
CVE-2024-4375 on NVD →
Master Slider – Responsive Touch Slider <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via ms_layer Shortcode
medium
The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_layer' shortcode in all versions up to, and including, 3.9.10 due to insufficient input sanitization and output escaping on the 'css_id' user supplied attribute. This makes it possible for...
- CVSS:
- 6.4
- Affected:
- up to 3.9.10
- Fixed in:
- 3.10.0
- Disclosed:
- Jun 17, 2024
CVE-2024-4375 on NVD →
Master Slider – Responsive Touch Slider [master-slider] < 3.9.10
unknown
[en] The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_slide' shortcode in all versions up to, and including, 3.9.9 due to insufficient input sanitization and output escaping on user supplied 'css_class' attribute. This makes it possible f...
- Affected:
- up to 3.9.10
- Fixed in:
- 3.9.10
- Disclosed:
- Jun 1, 2024
CVE-2023-6382 on NVD →
Master Slider - Responsive Touch Slider <= 3.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_slide' shortcode in all versions up to, and including, 3.9.9 due to insufficient input sanitization and output escaping on user supplied 'css_class' attribute. This makes it possible for au...
- CVSS:
- 6.4
- Affected:
- up to 3.9.9
- Fixed in:
- 3.9.10
- Disclosed:
- May 31, 2024
CVE-2023-6382 on NVD →
Master Slider – Responsive Touch Slider [master-slider] < 3.9.10
unknown
[en] The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_slide_info' shortcode in all versions up to, and including, 3.9.9 due to insufficient input sanitization and output escaping on user supplied 'tag_name' attribute. This makes it possib...
- Affected:
- up to 3.9.10
- Fixed in:
- 3.9.10
- Disclosed:
- May 21, 2024
CVE-2024-4470 on NVD →
Master Slider – Responsive Touch Slider <= 3.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_slide_info' shortcode in all versions up to, and including, 3.9.9 due to insufficient input sanitization and output escaping on user supplied 'tag_name' attribute. This makes it possible fo...
- CVSS:
- 6.4
- Affected:
- up to 3.9.9
- Fixed in:
- 3.9.10
- Disclosed:
- May 20, 2024
CVE-2024-4470 on NVD →
Master Slider – Responsive Touch Slider [master-slider] < 3.9.9
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Master Slider allows Stored XSS.This issue affects Master Slider: from n/a through 3.9.8.
- Affected:
- up to 3.9.9
- Fixed in:
- 3.9.9
- Disclosed:
- Apr 18, 2024
CVE-2024-32580 on NVD →
Master Slider – Responsive Touch Slider [master-slider] < 3.9.7
unknown
[en] Deserialization of Untrusted Data vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.9.5.
- Affected:
- up to 3.9.7
- Fixed in:
- 3.9.7
- Disclosed:
- Apr 18, 2024
CVE-2024-32600 on NVD →
Master Slider <= 3.9.5 - Unauthenticated PHP Object Injection
critical
The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.9.5 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable plugin....
- CVSS:
- 9.8
- Affected:
- up to 3.9.5
- Fixed in:
- 3.9.7
- Disclosed:
- Apr 16, 2024
CVE-2024-32600 on NVD →
Master Slider – Responsive Touch Slider <= 3.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.9.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level acc...
- CVSS:
- 6.4
- Affected:
- up to 3.9.8
- Fixed in:
- 3.9.9
- Disclosed:
- Apr 16, 2024
CVE-2024-32580 on NVD →
Master Slider – Responsive Touch Slider [master-slider] < 3.9.10
unknown
[en] The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slides callback functionality in all versions up to, and including, 3.9.5. This makes it possible for authenticated attackers, with editor-level access, to inject arbitrary web scripts in pages tha...
- Affected:
- up to 3.9.10
- Fixed in:
- 3.9.10
- Disclosed:
- Mar 2, 2024
CVE-2024-0611 on NVD →
Master Slider – Responsive Touch Slider [master-slider] < 3.10.0
unknown
[en] The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ms_slide shortcode in all versions up to, and including, 3.9.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica...
- Affected:
- up to 3.10.0
- Fixed in:
- 3.10.0
- Disclosed:
- Mar 2, 2024
CVE-2024-1449 on NVD →
Master Slider – Responsive Touch Slider [master-slider] < 3.10.0
unknown
[en] The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.9.3. This is due to missing or incorrect nonce validation on the 'process_bulk_action' function. This makes it possible for unauthenticated attackers to duplicate or...
- Affected:
- up to 3.10.0
- Fixed in:
- 3.10.0
- Disclosed:
- Mar 2, 2024
CVE-2023-6326 on NVD →
Master Slider – Responsive Touch Slider <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ms_slide shortcode in all versions up to, and including, 3.9.10 due to insufficient input sanitization and output escaping on the 'src' user supplied attributes. This makes it possible for auth...
- CVSS:
- 6.4
- Affected:
- up to 3.9.10
- Fixed in:
- 3.10.0
- Disclosed:
- Mar 1, 2024
CVE-2024-1449 on NVD →
Master Slider - Responsive Touch Slider <= 3.9.10 - Cross-Site Request Forgery via process_bulk_action
medium
The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.9.10. This is due to missing or incorrect nonce validation on the 'process_bulk_action' function. This makes it possible for unauthenticated attackers to duplicate or dele...
- CVSS:
- 5.4
- Affected:
- up to 3.9.10
- Fixed in:
- 3.10.0
- Disclosed:
- Mar 1, 2024
CVE-2023-6326 on NVD →
Master Slider – Responsive Touch Slider <= 3.9.9 - Authenticated(Editor+) Stored Cross-Site Scripting via slider callback
medium
The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slides callback functionality in all versions up to, and including, 3.9.9. This makes it possible for authenticated attackers, with editor-level access, to inject arbitrary web scripts in pages that wil...
- CVSS:
- 4.4
- Affected:
- up to 3.9.9
- Fixed in:
- 3.9.10
- Disclosed:
- Mar 1, 2024
CVE-2024-0611 on NVD →
Master Slider – Responsive Touch Slider [master-slider] < 3.7.5
unknown
[en] The Master Slider plugin 3.2.7 and 3.5.1 for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings value on Callback.
- Affected:
- up to 3.7.5
- Fixed in:
- 3.7.5
- Disclosed:
- Dec 23, 2018
CVE-2018-20368 on NVD →
Master Slider <= 3.7.0 - Authenticated Stored Cross-Site Scripting
medium
The Master Slider plugin for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings value on Callback.
- CVSS:
- 5.4
- Affected:
- up to 3.7.0
- Fixed in:
- 3.7.5
- Disclosed:
- Nov 14, 2018
CVE-2018-20368 on NVD →
Master Slider <= 2.7.1 - Cross-Site Scripting
medium
The Master Slider plugin for WordPress is vulnerable to Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user access...
- CVSS:
- 6.1
- Affected:
- up to 2.8.0
- Fixed in:
- 2.8.0
- Disclosed:
- Jul 16, 2016
Master Slider – Responsive Touch Slider [master-slider] < 2.8.0
unknown
The Master Slider plugin for WordPress is vulnerable to Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user access...
- Affected:
- up to 2.8.0
- Fixed in:
- 2.8.0
- Disclosed:
- Jul 16, 2016
Master Slider – Responsive Touch Slider [master-slider] < 2.8.0
unknown
Because of this vulnerability, the attackers can inject arbitrary web script or HTML.
Upgrade this plugin.
- Affected:
- up to 2.8.0
- Fixed in:
- 2.8.0
- Disclosed:
- Jul 13, 2016
Master Slider - Responsive Touch Slider <= 2.5.1 - Authenticated Blind SQL Injection
high
The Master Slider - Responsive Touch Slider plugin for WordPress is vulnerable to blind SQL Injection via the ‘orderby’ parameter in versions up to, and including, 2.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for a...
- CVSS:
- 8.8
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.2
- Disclosed:
- Aug 20, 2015
Master Slider – Responsive Touch Slider [master-slider] < 2.5.2
unknown
The Master Slider - Responsive Touch Slider plugin for WordPress is vulnerable to blind SQL Injection via the ‘orderby’ parameter in versions up to, and including, 2.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for a...
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.2
- Disclosed:
- Aug 20, 2015
Master Slider – Responsive Touch Slider [master-slider] < 2.5.2
unknown
Because of this vulnerability, authenticated users can execute arbitrary SQL commands.
Upgrade this plugin.
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.2
- Disclosed:
- Aug 20, 2015
Master Slider – Responsive Touch Slider [master-slider] <= 3.10.7 (unfixed)
unknown
- Affected:
- up to 3.10.7
- Fix:
- No patched version reported
Master Slider – Responsive Touch Slider [master-slider] < 3.10.9
unknown
- Affected:
- up to 3.10.9
- Fixed in:
- 3.10.9
CVE-2025-5291 on NVD →
Master Slider – Responsive Touch Slider [master-slider] < 2.5.2
unknown
The Master Slider – Responsive Touch Slider WordPress plugin was affected by an Authenticated Blind SQL Injection security vulnerability.
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.2
Master Slider – Responsive Touch Slider [master-slider] < 2.8.0
unknown
The Master Slider – Responsive Touch Slider WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability. In order to exploit this issue, the attacker has to lure/force a logged on WordPress Administrator into opening a malicious website/page.
- Affected:
- up to 2.8.0
- Fixed in:
- 2.8.0