plugin

Slider Hero Vulnerabilities

13 known security issues reported for the Slider Hero WordPress plugin. Most recent disclosed Aug 15, 2026.

1 high 4 medium

Running Slider Hero on your site? Check whether your installed version is affected.

Scan your site free

Slider Hero with Video Background, Animation <= 9.1.7 - Authenticated (Administrator+) SQL Injection via 'description' Slide Field (Second-Order via Duplicate)

medium

The Slider Hero plugin for WordPress is vulnerable to second-order SQL Injection in versions up to, and including, 9.1.7 via the qcld_sliderhero_duplicate() function. Slide data (description, title, btn, btn2, image_link, custom, etc.) is stored safely via $wpdb->update() with %s placeholders in the qchero_save_image A...

CVSS:
4.9
Affected:
up to 9.1.7
Fixed in:
9.1.8
Disclosed:
Aug 15, 2026

CVE-2026-17582 on NVD →

Slider Hero with Video Background, Animation [slider-hero] < 8.7.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Quantum Cloud Slider Hero allows Stored XSS.This issue affects Slider Hero: from n/a through 8.6.1.

Affected:
up to 8.7.0
Fixed in:
8.7.0
Disclosed:
Mar 27, 2024

CVE-2024-29922 on NVD →

Slider Hero <= 8.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Slider Hero with Animation, Video Background plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permi...

CVSS:
5.5
Affected:
up to 8.6.1
Fixed in:
8.7.0
Disclosed:
Mar 25, 2024

CVE-2024-29922 on NVD →

Slider Hero with Video Background, Animation [slider-hero] < 8.2.1

unknown

[en] The Slider Hero plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.2.0. This is due to missing or incorrect nonce validation on the qc_slider_hero_duplicate() function. This makes it possible for unauthenticated attackers to duplicate slides via a forged request gr...

Affected:
up to 8.2.1
Fixed in:
8.2.1
Disclosed:
Jul 12, 2023

CVE-2021-4424 on NVD →

Slider Hero with Video Background, Animation [slider-hero] < 8.2.1

unknown
Affected:
up to 8.2.1
Fixed in:
8.2.1
Disclosed:
Jun 7, 2023

CVE-2021-4342 on NVD →

Slider Hero with Video Background, Animation [slider-hero] < 8.4.4

unknown

[en] The Slider Hero WordPress plugin before 8.4.4 does not escape the slider Name, which could allow high-privileged users to perform Cross-Site Scripting attacks.

Affected:
up to 8.4.4
Fixed in:
8.4.4
Disclosed:
Sep 26, 2022

CVE-2022-3074 on NVD →

Slider Hero <= 8.4.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Slider Hero plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slider title parameter in versions up to, and including, 8.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inje...

CVSS:
5.5
Affected:
up to 8.4.3
Fixed in:
8.4.4
Disclosed:
Sep 5, 2022

CVE-2022-3074 on NVD →

Slider Hero with Video Background, Animation [slider-hero] < 8.2.7

unknown

[en] The Slider Hero with Animation, Video Background & Intro Maker WordPress plugin before 8.2.7 does not sanitise or escape the id attribute of its hero-button shortcode before using it in a SQL statement, allowing users with a role as low as Contributor to perform SQL injection.

Affected:
up to 8.2.7
Fixed in:
8.2.7
Disclosed:
Aug 23, 2021

CVE-2021-24506 on NVD →

Slider Hero with Animation, Video Background & Intro Maker <= 8.2.6 - SQL Injection

high

The Slider Hero with Animation, Video Background & Intro Maker WordPress plugin before 8.2.7 does not sanitise or escape the id attribute of its hero-button shortcode before using it in a SQL statement, allowing users with a role as low as Contributor to perform SQL injection.

CVSS:
8.8
Affected:
up to 8.2.7
Fixed in:
8.2.7
Disclosed:
Jul 26, 2021

CVE-2021-24506 on NVD →

Slider Hero <= 8.2.0 - Cross-Site Request Forgery Bypass

medium

The Slider Hero plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.2.0. This is due to missing or incorrect nonce validation on the qc_slider_hero_duplicate() function. This makes it possible for unauthenticated attackers to duplicate slides via a forged request granted...

CVSS:
4.3
Affected:
up to 8.2.0
Fixed in:
8.2.1
Disclosed:
Jul 5, 2021

CVE-2021-4424 on NVD →

Slider Hero with Video Background, Animation [slider-hero] < 8.2.1

unknown

Cross-Site Request Forgery (CSRF) vulnerability discovered by Jerome Bruandet (NinTechNet) in WordPress Slider Hero plugin (versions < = 8.2.0).

Affected:
up to 8.2.1
Fixed in:
8.2.1
Disclosed:
Jul 5, 2021

Slider Hero with Video Background, Animation [slider-hero] < 8.2.1

unknown

Multiple plugins are affected by CSRF bypass as they do not properly check for the nonce due to a logic flaw. This could allow attackers to make logged in users do unwanted actions

Affected:
up to 8.2.1
Fixed in:
8.2.1

Slider Hero with Video Background, Animation [slider-hero] < 8.2.1

unknown

Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.

Affected:
up to 8.2.1
Fixed in:
8.2.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database