Slider, Gallery, and Carousel by MetaSlider <= 3.111.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'delay' Post Meta Setting
medium
The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'delay' Post Meta Setting in all versions up to, and including, 3.111.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...
- CVSS:
- 6.4
- Affected:
- up to 3.111.0
- Fixed in:
- 3.111.1
- Disclosed:
- Aug 5, 2026
CVE-2026-18400 on NVD →
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider <= 3.106.0 - Authenticated (Editor+) Remote Code Execution
high
The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.106.0. This makes it possible for authenticated attackers, with Editor-level access and above, to execute code on the server.
- CVSS:
- 7.2
- Affected:
- up to 3.106.0
- Fixed in:
- 3.107.0
- Disclosed:
- Apr 20, 2026
CVE-2026-39465 on NVD →
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider <= 3.106.0 - Authenticated (Editor+) PHP Object Injection
medium
The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.106.0 via deserialization of untrusted input. This makes it possible for authenticated attackers, with editor-level access and above, to inject a PH...
- CVSS:
- 6.6
- Affected:
- up to 3.106.0
- Fixed in:
- 3.107.0
- Disclosed:
- Apr 20, 2026
CVE-2026-39467 on NVD →
Slider, Gallery, and Carousel by MetaSlider <= 3.98.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via aria-label Parameter
medium
The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘aria-label’ parameter in all versions up to, and including, 3.98.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-l...
- CVSS:
- 6.4
- Affected:
- up to 3.98.0
- Fixed in:
- 3.99.0
- Disclosed:
- Jun 13, 2025
CVE-2025-5337 on NVD →
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider <= 3.94.0 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.94.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, w...
- CVSS:
- 4.4
- Affected:
- up to 3.94.0
- Fixed in:
- 3.95.0
- Disclosed:
- Mar 2, 2025
CVE-2025-1203 on NVD →
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider <= 3.94.0 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.94.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, w...
- CVSS:
- 4.4
- Affected:
- up to 3.94.0
- Fixed in:
- 3.95.0
- Disclosed:
- Mar 2, 2025
CVE-2025-1062 on NVD →
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider] < 3.95.0
unknown
[en] Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection. This issue affects Responsive Slider by MetaSlider: from n/a through 3.94.0.
- Affected:
- up to 3.95.0
- Fixed in:
- 3.95.0
- Disclosed:
- Feb 22, 2025
CVE-2025-26763 on NVD →
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider <= 3.94.0 - Authenticated (Editor+) PHP Object Injection
high
The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.94.0 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a...
- CVSS:
- 7.2
- Affected:
- up to 3.94.0
- Fixed in:
- 3.95.0
- Disclosed:
- Feb 14, 2025
CVE-2025-26763 on NVD →
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider] < 3.92.1
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in MetaSlider Responsive Slider by MetaSlider allows Cross Site Request Forgery. This issue affects Responsive Slider by MetaSlider: from n/a through 3.92.0.
- Affected:
- up to 3.92.1
- Fixed in:
- 3.92.1
- Disclosed:
- Jan 27, 2025
CVE-2025-24533 on NVD →
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider <= 3.92.0 - Cross-Site Request Forgery
medium
The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.92.0. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to...
- CVSS:
- 4.3
- Affected:
- up to 3.92.0
- Fixed in:
- 3.92.1
- Disclosed:
- Nov 9, 2024
CVE-2025-24533 on NVD →
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider] < 3.70.1
unknown
[en] The Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Slideshows plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'metaslider' shortcode in all versions up to, and including, 3.70.0 due to insufficient input sanitization and output escaping on user supplied attrib...
- Affected:
- up to 3.70.1
- Fixed in:
- 3.70.1
- Disclosed:
- Apr 11, 2024
CVE-2024-3285 on NVD →
Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Slideshows <= 3.70.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via metaslider Shortcode
medium
The Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Slideshows plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'metaslider' shortcode in all versions up to, and including, 3.70.0 due to insufficient input sanitization and output escaping on user supplied attributes....
- CVSS:
- 6.4
- Affected:
- up to 3.70.0
- Fixed in:
- 3.70.1
- Disclosed:
- Apr 10, 2024
CVE-2024-3285 on NVD →
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider] < 3.29.1
unknown
[en] The Slider, Gallery, and Carousel by MetaSlider WordPress plugin 3.29.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected:
- up to 3.29.1
- Fixed in:
- 3.29.1
- Disclosed:
- Apr 17, 2023
CVE-2023-1473 on NVD →
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider] < 3.29.1
unknown
Update the WordPress Meta Slider plugin to the latest available version (at least 3.29.1).
WordFence discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Meta Slider Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML pa...
- Affected:
- up to 3.29.1
- Fixed in:
- 3.29.1
- Disclosed:
- Mar 22, 2023
Slider, Gallery, and Carousel by MetaSlider <= 3.29.0 - Reflected Cross-Site Scripting
medium
The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 3.29.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...
- CVSS:
- 6.1
- Affected:
- up to 3.29.0
- Fixed in:
- 3.29.1
- Disclosed:
- Mar 20, 2023
CVE-2023-1473 on NVD →
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider] < 3.29.1
unknown
The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 3.29.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...
- Affected:
- up to 3.29.1
- Fixed in:
- 3.29.1
- Disclosed:
- Mar 20, 2023
Appsero <= 1.2.1 - Missing Authorization
medium
The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with subscriber-level permissio...
- CVSS:
- 4.3
- Affected:
- up to 3.28.0
- Fixed in:
- 3.28.1
- Disclosed:
- Dec 16, 2022
Appsero <= 1.2.0 - Cross-Site Request Forgery
medium
The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers to invoke this function inten...
- CVSS:
- 4.3
- Affected:
- up to 3.28.0
- Fixed in:
- 3.28.1
- Disclosed:
- Dec 14, 2022
CVE-2022-47150 on NVD →
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider] < 3.27.9
unknown
[en] The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.27.9 does not sanitise and escape some of its Gallery Image parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example i...
- Affected:
- up to 3.27.9
- Fixed in:
- 3.27.9
- Disclosed:
- Oct 10, 2022
CVE-2022-2823 on NVD →
Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Plugin <= 3.27.8 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The "Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.27.8 due to insufficient input sanitization and output escaping of some of its parameters. This makes it possible for authenticated attack...
- CVSS:
- 5.5
- Affected:
- 3.27.8 – 3.27.8
- Fixed in:
- 3.27.9
- Disclosed:
- Sep 14, 2022
CVE-2022-2823 on NVD →
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider] < 3.17.2
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by Vishnupriya Ilango (Fortinet FortiGuard Labs) in WordPress Responsive Slider by MetaSlider plugin (versions <= 3.17.1).
- Affected:
- up to 3.17.2
- Fixed in:
- 3.17.2
- Disclosed:
- Sep 17, 2020
Slider, Gallery, and Carousel by MetaSlider <= 3.17.1 - Authenticated Stored Cross-Site Scripting
medium
The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross Site Scripting in versions up to, and including, 3.17.1. The patch adds extra filtering of captions using HTML Purifier where there appeared to be a stored cross-site scripting vulnerability to accounts with sufficient pr...
- CVSS:
- 6.4
- Affected:
- up to 3.17.2
- Fixed in:
- 3.17.2
- Disclosed:
- Aug 28, 2020
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider] < 3.17.2
unknown
The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross Site Scripting in versions up to, and including, 3.17.1. The patch adds extra filtering of captions using HTML Purifier where there appeared to be a stored cross-site scripting vulnerability to accounts with sufficient pr...
- Affected:
- up to 3.17.2
- Fixed in:
- 3.17.2
- Disclosed:
- Aug 28, 2020
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider] < 2.2
unknown
This plugin is prone to a full path disclosure vulnerability.
Update the plugin.
- Affected:
- up to 2.2
- Fixed in:
- 2.2
- Disclosed:
- Oct 27, 2015
Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Plugin <= 2.5 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the Meta Slider (ml-slider) plugin 2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter to wp-admin/admin.php.
- CVSS:
- 6.1
- Affected:
- up to 2.5
- Fixed in:
- 2.6
- Disclosed:
- Aug 1, 2014
CVE-2014-4846 on NVD →
Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Plugin <= 2.1.6 - Full Path Disclosure
medium
The Meta Slider plugin for WordPress is vulnerable to full path disclosure in versions up to, and including, 2.1.6. This makes it possible for unauthenticated attackers to discover the path of folders and files hosted on a vulnerable system.
- CVSS:
- 5.3
- Affected:
- up to 2.1.6
- Fixed in:
- 2.2
- Disclosed:
- Aug 1, 2014
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider] < 2.2
unknown
The Meta Slider plugin for WordPress is vulnerable to full path disclosure in versions up to, and including, 2.1.6. This makes it possible for unauthenticated attackers to discover the path of folders and files hosted on a vulnerable system.
- Affected:
- up to 2.2
- Fixed in:
- 2.2
- Disclosed:
- Aug 1, 2014
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider] < 2.6
unknown
[en] Cross-site scripting (XSS) vulnerability in the Meta Slider (ml-slider) plugin 2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter to wp-admin/admin.php.
- Affected:
- up to 2.6
- Fixed in:
- 2.6
- Disclosed:
- Jul 10, 2014
CVE-2014-4846 on NVD →
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider] < 3.95.0
unknown
- Affected:
- up to 3.95.0
- Fixed in:
- 3.95.0
CVE-2025-1203 on NVD →
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider] < 3.95.0
unknown
- Affected:
- up to 3.95.0
- Fixed in:
- 3.95.0
CVE-2025-1062 on NVD →
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider] < 3.99.0
unknown
- Affected:
- up to 3.99.0
- Fixed in:
- 3.99.0
CVE-2025-5337 on NVD →
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider] < 2.2
unknown
The Responsive Slider by MetaSlider – Slider and Carousel Plugin for WordPress WordPress plugin was affected by a Multiple Full Path Disclosure security vulnerability.
- Affected:
- up to 2.2
- Fixed in:
- 2.2
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider] < 3.17.2
unknown
Vishnupriya Ilango, from Fortinet's FortiGuard Lab, discovered a stored Cross-Site Scripting (XSS) vulnerability in Metaslider plugin (v3.17.1), which exists in Image caption or description parameter in the slide creation module.
- Affected:
- up to 3.17.2
- Fixed in:
- 3.17.2
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider] < 3.28.1
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 3.28.1
- Fixed in:
- 3.28.1
CVE-2022-47150 on NVD →