Slideshow [slideshow-jquery-image-gallery] < 2.1.15 (closed)
unknown
Update plugin.
An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Slideshow Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit you...
- Affected:
- up to 2.1.15
- Fixed in:
- 2.1.15
- Disclosed:
- Nov 27, 2023
Slideshow [slideshow-jquery-image-gallery] < 2.1.13 (closed)
unknown
Update plugin.
Janek Vind discovered and reported this Multiple Vulnerabilities vulnerability in WordPress Slideshow Plugin. Multiple vulnerabilities were found. Due to the large number of vulnerabilities, this has been grouped in this category. This vulnerability has been fixed in version 2.1.13.
- Affected:
- up to 2.1.13
- Fixed in:
- 2.1.13
- Disclosed:
- Nov 27, 2023
Slideshow [slideshow-jquery-image-gallery] < 1.1 (closed)
unknown
Update the plugin.
waraxe discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Slideshow Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site....
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Oct 17, 2023
Slideshow [slideshow-jquery-image-gallery] <= 2.3.1 (unfixed + closed)
unknown
[en] The Slideshow WordPress plugin through 2.3.1 does not sanitize and escape some of its default slideshow settings, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- Affected:
- up to 2.3.1
- Fix:
- No patched version reported
- Disclosed:
- May 30, 2022
CVE-2022-1299 on NVD →
Slideshow [slideshow-jquery-image-gallery] <= 2.3.1 (unfixed + closed)
unknown
Stored Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Slideshow plugin (versions <= 2.3.1).<br />
Deactivate and delete. This plugin has been closed as of April 11, 2022 and is not available for download. This closure is temporary, pending a full review.<br />
- Affected:
- up to 2.3.1
- Fix:
- No patched version reported
- Disclosed:
- May 10, 2022
Slideshow [slideshow-jquery-image-gallery] <= 2.3.1 (unfixed + closed)
unknown
Stored Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Slideshow plugin (versions <= 2.3.1).
Deactivate and delete. This plugin has been closed as of April 11, 2022 and is not available for download. This closure is temporary, pending a full review.
- Affected:
- up to 2.3.1
- Fix:
- No patched version reported
- Disclosed:
- May 10, 2022
Slideshow <= 2.3.1 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Slideshow WordPress plugin through 2.3.1 does not sanitize and escape some of its default slideshow settings, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- CVSS:
- 4.8
- Affected:
- up to 2.3.1
- Fix:
- No patched version reported
- Disclosed:
- May 9, 2022
CVE-2022-1299 on NVD →
Slideshow [slideshow-jquery-image-gallery] >= 2.2.8 - <= 2.2.21 (closed)
unknown
[en] The SlideshowPluginSlideshowStylesheet::loadStylesheetByAJAX function in the Slideshow plugin 2.2.8 through 2.2.21 for Wordpress allows remote attackers to read arbitrary Wordpress option values.
- Affected:
- 2.2.8 – 2.2.21
- Fixed in:
- 2.2.21
- Disclosed:
- Jun 8, 2017
CVE-2015-3634 on NVD →
Slideshow [slideshow-jquery-image-gallery] < 2.1.15 (closed)
unknown
This plugin is prone to multiple script insertion vulnerabilities. Attackers can conduct script insertion attacks.
Update plugin.
- Affected:
- up to 2.1.15
- Fixed in:
- 2.1.15
- Disclosed:
- Nov 27, 2015
Slideshow [slideshow-jquery-image-gallery] < 2.1.13 (closed)
unknown
This plugin is prone to reflected cross site scripting vulnerability in "views/SlideshowPlugin/slideshow.php", "views/SlideshowPluginPostType/settings.php", "views/SlideshowPluginPostType/style-settings.php" and full path disclosure in multiple scripts.
Update plugin.
- Affected:
- up to 2.1.13
- Fixed in:
- 2.1.13
- Disclosed:
- Nov 27, 2015
Slideshow 2.2.8 - 2.2.21 - Information Exposure
high
The SlideshowPluginSlideshowStylesheet::loadStylesheetByAJAX function in the Slideshow plugin 2.2.8 through 2.2.21 for Wordpress allows remote attackers to read arbitrary Wordpress option values.
- CVSS:
- 7.5
- Affected:
- 2.2.8 – 2.2.21
- Fixed in:
- 2.2.22
- Disclosed:
- May 2, 2015
CVE-2015-3634 on NVD →
Slideshow < 2.1.13 - Cross-Site Scripting and Sensitive Information Disclosure
medium
The Slideshow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 2.1.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if the...
- CVSS:
- 6.1
- Affected:
- up to 2.1.12
- Fixed in:
- 2.1.13
- Disclosed:
- Oct 17, 2012
Slideshow [slideshow-jquery-image-gallery] < 1.1 (closed)
unknown
WordPress Slideshow plugin is prone to multiple cross-site scripting vulnerabilities. These vulnerabilities allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. In that way, an attacker can steal cookie-based authentication credentials and launch...
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Oct 17, 2012
Slideshow [slideshow-jquery-image-gallery] < 2.1.13 (closed)
unknown
The Slideshow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 2.1.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if the...
- Affected:
- up to 2.1.13
- Fixed in:
- 2.1.13
- Disclosed:
- Oct 17, 2012
Slideshow [slideshow-jquery-image-gallery] <= 2.3.1 (unfixed + closed)
unknown
The plugin does not sanitise and escape some of its Slideshow settings, which could allow users with a role as low as Author to perform Cross-Site Scripting attacks
- Affected:
- up to 2.3.1
- Fix:
- No patched version reported
Slideshow [slideshow-jquery-image-gallery] < 2.1.15 (closed)
unknown
The Slideshow WordPress plugin was affected by a Multiple Script Insertion Vulnerabilities security vulnerability.
- Affected:
- up to 2.1.15
- Fixed in:
- 2.1.15
Slideshow [slideshow-jquery-image-gallery] < 2.1.13 (closed)
unknown
The Slideshow WordPress plugin was affected by a Multiple Vulnerabilities security vulnerability.
- Affected:
- up to 2.1.13
- Fixed in:
- 2.1.13
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database