Slider Hero with Video Background, Animation <= 9.1.7 - Authenticated (Administrator+) SQL Injection via 'description' Slide Field (Second-Order via Duplicate)
medium
The Slider Hero plugin for WordPress is vulnerable to second-order SQL Injection in versions up to, and including, 9.1.7 via the qcld_sliderhero_duplicate() function. Slide data (description, title, btn, btn2, image_link, custom, etc.) is stored safely via $wpdb->update() with %s placeholders in the qchero_save_image A...
- CVSS:
- 4.9
- Affected:
- up to 9.1.7
- Fixed in:
- 9.1.8
- Disclosed:
- Aug 15, 2026
CVE-2026-17582 on NVD →
Slider Hero with Video Background, Animation [slider-hero] < 8.7.0
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Quantum Cloud Slider Hero allows Stored XSS.This issue affects Slider Hero: from n/a through 8.6.1.
- Affected:
- up to 8.7.0
- Fixed in:
- 8.7.0
- Disclosed:
- Mar 27, 2024
CVE-2024-29922 on NVD →
Slider Hero <= 8.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Slider Hero with Animation, Video Background plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permi...
- CVSS:
- 5.5
- Affected:
- up to 8.6.1
- Fixed in:
- 8.7.0
- Disclosed:
- Mar 25, 2024
CVE-2024-29922 on NVD →
Slider Hero with Video Background, Animation [slider-hero] < 8.2.1
unknown
[en] The Slider Hero plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.2.0. This is due to missing or incorrect nonce validation on the qc_slider_hero_duplicate() function. This makes it possible for unauthenticated attackers to duplicate slides via a forged request gr...
- Affected:
- up to 8.2.1
- Fixed in:
- 8.2.1
- Disclosed:
- Jul 12, 2023
CVE-2021-4424 on NVD →
Slider Hero with Video Background, Animation [slider-hero] < 8.2.1
unknown
- Affected:
- up to 8.2.1
- Fixed in:
- 8.2.1
- Disclosed:
- Jun 7, 2023
CVE-2021-4342 on NVD →
Slider Hero with Video Background, Animation [slider-hero] < 8.4.4
unknown
[en] The Slider Hero WordPress plugin before 8.4.4 does not escape the slider Name, which could allow high-privileged users to perform Cross-Site Scripting attacks.
- Affected:
- up to 8.4.4
- Fixed in:
- 8.4.4
- Disclosed:
- Sep 26, 2022
CVE-2022-3074 on NVD →
Slider Hero <= 8.4.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Slider Hero plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slider title parameter in versions up to, and including, 8.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inje...
- CVSS:
- 5.5
- Affected:
- up to 8.4.3
- Fixed in:
- 8.4.4
- Disclosed:
- Sep 5, 2022
CVE-2022-3074 on NVD →
Slider Hero with Video Background, Animation [slider-hero] < 8.2.7
unknown
[en] The Slider Hero with Animation, Video Background & Intro Maker WordPress plugin before 8.2.7 does not sanitise or escape the id attribute of its hero-button shortcode before using it in a SQL statement, allowing users with a role as low as Contributor to perform SQL injection.
- Affected:
- up to 8.2.7
- Fixed in:
- 8.2.7
- Disclosed:
- Aug 23, 2021
CVE-2021-24506 on NVD →
Slider Hero with Animation, Video Background & Intro Maker <= 8.2.6 - SQL Injection
high
The Slider Hero with Animation, Video Background & Intro Maker WordPress plugin before 8.2.7 does not sanitise or escape the id attribute of its hero-button shortcode before using it in a SQL statement, allowing users with a role as low as Contributor to perform SQL injection.
- CVSS:
- 8.8
- Affected:
- up to 8.2.7
- Fixed in:
- 8.2.7
- Disclosed:
- Jul 26, 2021
CVE-2021-24506 on NVD →
Slider Hero <= 8.2.0 - Cross-Site Request Forgery Bypass
medium
The Slider Hero plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.2.0. This is due to missing or incorrect nonce validation on the qc_slider_hero_duplicate() function. This makes it possible for unauthenticated attackers to duplicate slides via a forged request granted...
- CVSS:
- 4.3
- Affected:
- up to 8.2.0
- Fixed in:
- 8.2.1
- Disclosed:
- Jul 5, 2021
CVE-2021-4424 on NVD →
Slider Hero with Video Background, Animation [slider-hero] < 8.2.1
unknown
Cross-Site Request Forgery (CSRF) vulnerability discovered by Jerome Bruandet (NinTechNet) in WordPress Slider Hero plugin (versions < = 8.2.0).
- Affected:
- up to 8.2.1
- Fixed in:
- 8.2.1
- Disclosed:
- Jul 5, 2021
Slider Hero with Video Background, Animation [slider-hero] < 8.2.1
unknown
Multiple plugins are affected by CSRF bypass as they do not properly check for the nonce due to a logic flaw. This could allow attackers to make logged in users do unwanted actions
- Affected:
- up to 8.2.1
- Fixed in:
- 8.2.1
Slider Hero with Video Background, Animation [slider-hero] < 8.2.1
unknown
Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.
- Affected:
- up to 8.2.1
- Fixed in:
- 8.2.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database