plugin

Meta Slider And Carousel With Lightbox Vulnerabilities

7 known security issues reported for the Meta Slider And Carousel With Lightbox WordPress plugin. Most recent disclosed Apr 9, 2026.

1 critical 3 medium

Running Meta Slider And Carousel With Lightbox on your site? Check whether your installed version is affected.

Scan your site free

Essentialplugin Plugins (Various Versions) - Injected Backdoor

critical

All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to the plugin being sold to a malicious threat actor that embedded a backdoor in all of the plugin's they acquired. This makes it possible for the threat actor to maintain a persistent backdoor and injec...

CVSS:
9.8
Affected:
2.0.8 – 2.0.8
Fixed in:
2.0.8.1
Disclosed:
Apr 9, 2026

CVE-2026-6443 on NVD →

Meta Slider and Carousel with Lightbox [meta-slider-and-carousel-with-lightbox] < 1.7

unknown

[en] Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Meta slider and carousel with lightbox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Meta slider and carousel with lightbox: from n/a through 1.6.2.

Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Dec 9, 2024

CVE-2023-25703 on NVD →

Meta Slider and Carousel with Lightbox [meta-slider-and-carousel-with-lightbox] < 2.0.2

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Essential Plugin Meta slider and carousel with lightbox allows Stored XSS.This issue affects Meta slider and carousel with lightbox: from n/a through 2.0.1.

Affected:
up to 2.0.2
Fixed in:
2.0.2
Disclosed:
Oct 6, 2024

CVE-2024-47307 on NVD →

Meta slider and carousel with lightbox <= 2.0.1 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Meta slider and carousel with lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web...

CVSS:
6.4
Affected:
up to 2.0.1
Fixed in:
2.0.2
Disclosed:
Sep 25, 2024

CVE-2024-47307 on NVD →

Multiple WPOnlineSupport Plugins <= (Various Versions) - Missing Authorization to Notice Dismissal

medium

Multiple WPOnlineSupport plugins for WordPress are vulnerable to unauthorized modification of data due to a missing capability check on the wpos_anylc_admin_init_process() function hooked via admin_init in various versions. This makes it possible for unauthenticated attackers to dismiss a license notice.

CVSS:
5.3
Affected:
up to 1.8.2
Fixed in:
1.8.3
Disclosed:
Aug 16, 2023

CVE-2023-40200 on NVD →

Meta Slider and Carousel with Lightbox <= 1.6.2 - Cross-Site Request Forgery

medium

The Meta Slider and Carousel with Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.2. This is due to missing or incorrect nonce validation on the 'wp_igsp_get_attachment_edit_form' and 'wp_igsp_save_attachment_data' functions. This makes it possible for una...

CVSS:
5.4
Affected:
up to 1.6.2
Fixed in:
1.7
Disclosed:
Feb 15, 2023

CVE-2023-25703 on NVD →

Meta Slider and Carousel with Lightbox [meta-slider-and-carousel-with-lightbox] < 1.8.3

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 1.8.3
Fixed in:
1.8.3

CVE-2023-40200 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database