plugin

Ml Slider Vulnerabilities

34 known security issues reported for the Ml Slider WordPress plugin. Most recent disclosed Aug 5, 2026.

2 high 14 medium

Running Ml Slider on your site? Check whether your installed version is affected.

Scan your site free

Slider, Gallery, and Carousel by MetaSlider <= 3.111.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'delay' Post Meta Setting

medium

The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'delay' Post Meta Setting in all versions up to, and including, 3.111.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...

CVSS:
6.4
Affected:
up to 3.111.0
Fixed in:
3.111.1
Disclosed:
Aug 5, 2026

CVE-2026-18400 on NVD →

Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider <= 3.106.0 - Authenticated (Editor+) Remote Code Execution

high

The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.106.0. This makes it possible for authenticated attackers, with Editor-level access and above, to execute code on the server.

CVSS:
7.2
Affected:
up to 3.106.0
Fixed in:
3.107.0
Disclosed:
Apr 20, 2026

CVE-2026-39465 on NVD →

Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider <= 3.106.0 - Authenticated (Editor+) PHP Object Injection

medium

The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.106.0 via deserialization of untrusted input. This makes it possible for authenticated attackers, with editor-level access and above, to inject a PH...

CVSS:
6.6
Affected:
up to 3.106.0
Fixed in:
3.107.0
Disclosed:
Apr 20, 2026

CVE-2026-39467 on NVD →

Slider, Gallery, and Carousel by MetaSlider <= 3.98.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via aria-label Parameter

medium

The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘aria-label’ parameter in all versions up to, and including, 3.98.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-l...

CVSS:
6.4
Affected:
up to 3.98.0
Fixed in:
3.99.0
Disclosed:
Jun 13, 2025

CVE-2025-5337 on NVD →

Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider <= 3.94.0 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.94.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, w...

CVSS:
4.4
Affected:
up to 3.94.0
Fixed in:
3.95.0
Disclosed:
Mar 2, 2025

CVE-2025-1203 on NVD →

Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider <= 3.94.0 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.94.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, w...

CVSS:
4.4
Affected:
up to 3.94.0
Fixed in:
3.95.0
Disclosed:
Mar 2, 2025

CVE-2025-1062 on NVD →

Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.95.0

unknown

[en] Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection. This issue affects Responsive Slider by MetaSlider: from n/a through 3.94.0.

Affected:
up to 3.95.0
Fixed in:
3.95.0
Disclosed:
Feb 22, 2025

CVE-2025-26763 on NVD →

Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider <= 3.94.0 - Authenticated (Editor+) PHP Object Injection

high

The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.94.0 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a...

CVSS:
7.2
Affected:
up to 3.94.0
Fixed in:
3.95.0
Disclosed:
Feb 14, 2025

CVE-2025-26763 on NVD →

Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.92.1

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in MetaSlider Responsive Slider by MetaSlider allows Cross Site Request Forgery. This issue affects Responsive Slider by MetaSlider: from n/a through 3.92.0.

Affected:
up to 3.92.1
Fixed in:
3.92.1
Disclosed:
Jan 27, 2025

CVE-2025-24533 on NVD →

Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider <= 3.92.0 - Cross-Site Request Forgery

medium

The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.92.0. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to...

CVSS:
4.3
Affected:
up to 3.92.0
Fixed in:
3.92.1
Disclosed:
Nov 9, 2024

CVE-2025-24533 on NVD →

Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.70.1

unknown

[en] The Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Slideshows plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'metaslider' shortcode in all versions up to, and including, 3.70.0 due to insufficient input sanitization and output escaping on user supplied attrib...

Affected:
up to 3.70.1
Fixed in:
3.70.1
Disclosed:
Apr 11, 2024

CVE-2024-3285 on NVD →

Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Slideshows <= 3.70.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via metaslider Shortcode

medium

The Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Slideshows plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'metaslider' shortcode in all versions up to, and including, 3.70.0 due to insufficient input sanitization and output escaping on user supplied attributes....

CVSS:
6.4
Affected:
up to 3.70.0
Fixed in:
3.70.1
Disclosed:
Apr 10, 2024

CVE-2024-3285 on NVD →

Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.29.1

unknown

[en] The Slider, Gallery, and Carousel by MetaSlider WordPress plugin 3.29.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Affected:
up to 3.29.1
Fixed in:
3.29.1
Disclosed:
Apr 17, 2023

CVE-2023-1473 on NVD →

Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.29.1

unknown

Update the WordPress Meta Slider plugin to the latest available version (at least 3.29.1). WordFence discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Meta Slider Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML pa...

Affected:
up to 3.29.1
Fixed in:
3.29.1
Disclosed:
Mar 22, 2023

Slider, Gallery, and Carousel by MetaSlider <= 3.29.0 - Reflected Cross-Site Scripting

medium

The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 3.29.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...

CVSS:
6.1
Affected:
up to 3.29.0
Fixed in:
3.29.1
Disclosed:
Mar 20, 2023

CVE-2023-1473 on NVD →

Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.29.1

unknown

The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 3.29.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...

Affected:
up to 3.29.1
Fixed in:
3.29.1
Disclosed:
Mar 20, 2023

Appsero <= 1.2.1 - Missing Authorization

medium

The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with subscriber-level permissio...

CVSS:
4.3
Affected:
up to 3.28.0
Fixed in:
3.28.1
Disclosed:
Dec 16, 2022

Appsero <= 1.2.0 - Cross-Site Request Forgery

medium

The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers to invoke this function inten...

CVSS:
4.3
Affected:
up to 3.28.0
Fixed in:
3.28.1
Disclosed:
Dec 14, 2022

CVE-2022-47150 on NVD →

Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.27.9

unknown

[en] The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.27.9 does not sanitise and escape some of its Gallery Image parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example i...

Affected:
up to 3.27.9
Fixed in:
3.27.9
Disclosed:
Oct 10, 2022

CVE-2022-2823 on NVD →

Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Plugin <= 3.27.8 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The "Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.27.8 due to insufficient input sanitization and output escaping of some of its parameters. This makes it possible for authenticated attack...

CVSS:
5.5
Affected:
3.27.8 – 3.27.8
Fixed in:
3.27.9
Disclosed:
Sep 14, 2022

CVE-2022-2823 on NVD →

Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.17.2

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by Vishnupriya Ilango (Fortinet FortiGuard Labs) in WordPress Responsive Slider by MetaSlider plugin (versions <= 3.17.1).

Affected:
up to 3.17.2
Fixed in:
3.17.2
Disclosed:
Sep 17, 2020

Slider, Gallery, and Carousel by MetaSlider <= 3.17.1 - Authenticated Stored Cross-Site Scripting

medium

The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross Site Scripting in versions up to, and including, 3.17.1. The patch adds extra filtering of captions using HTML Purifier where there appeared to be a stored cross-site scripting vulnerability to accounts with sufficient pr...

CVSS:
6.4
Affected:
up to 3.17.2
Fixed in:
3.17.2
Disclosed:
Aug 28, 2020

Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.17.2

unknown

The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross Site Scripting in versions up to, and including, 3.17.1. The patch adds extra filtering of captions using HTML Purifier where there appeared to be a stored cross-site scripting vulnerability to accounts with sufficient pr...

Affected:
up to 3.17.2
Fixed in:
3.17.2
Disclosed:
Aug 28, 2020

Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 2.2

unknown

This plugin is prone to a full path disclosure vulnerability. Update the plugin.

Affected:
up to 2.2
Fixed in:
2.2
Disclosed:
Oct 27, 2015

Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Plugin <= 2.5 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the Meta Slider (ml-slider) plugin 2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter to wp-admin/admin.php.

CVSS:
6.1
Affected:
up to 2.5
Fixed in:
2.6
Disclosed:
Aug 1, 2014

CVE-2014-4846 on NVD →

Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Plugin <= 2.1.6 - Full Path Disclosure

medium

The Meta Slider plugin for WordPress is vulnerable to full path disclosure in versions up to, and including, 2.1.6. This makes it possible for unauthenticated attackers to discover the path of folders and files hosted on a vulnerable system.

CVSS:
5.3
Affected:
up to 2.1.6
Fixed in:
2.2
Disclosed:
Aug 1, 2014

Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 2.2

unknown

The Meta Slider plugin for WordPress is vulnerable to full path disclosure in versions up to, and including, 2.1.6. This makes it possible for unauthenticated attackers to discover the path of folders and files hosted on a vulnerable system.

Affected:
up to 2.2
Fixed in:
2.2
Disclosed:
Aug 1, 2014

Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 2.6

unknown

[en] Cross-site scripting (XSS) vulnerability in the Meta Slider (ml-slider) plugin 2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter to wp-admin/admin.php.

Affected:
up to 2.6
Fixed in:
2.6
Disclosed:
Jul 10, 2014

CVE-2014-4846 on NVD →

Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.95.0

unknown
Affected:
up to 3.95.0
Fixed in:
3.95.0

CVE-2025-1203 on NVD →

Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.95.0

unknown
Affected:
up to 3.95.0
Fixed in:
3.95.0

CVE-2025-1062 on NVD →

Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.99.0

unknown
Affected:
up to 3.99.0
Fixed in:
3.99.0

CVE-2025-5337 on NVD →

Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 2.2

unknown

The Responsive Slider by MetaSlider &ndash; Slider and Carousel Plugin for WordPress WordPress plugin was affected by a Multiple Full Path Disclosure security vulnerability.

Affected:
up to 2.2
Fixed in:
2.2

Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.17.2

unknown

Vishnupriya Ilango, from Fortinet&#039;s FortiGuard Lab, discovered a stored Cross-Site Scripting (XSS) vulnerability in Metaslider plugin (v3.17.1), which exists in Image caption or description parameter in the slide creation module.

Affected:
up to 3.17.2
Fixed in:
3.17.2

Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.28.1

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 3.28.1
Fixed in:
3.28.1

CVE-2022-47150 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database