Thumbnail Slider With Lightbox <= 1.0.21 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
medium
The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FancyBox in all versions up to, and including, 1.0.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to injec...
- CVSS:
- 6.4
- Affected:
- up to 1.0.21
- Fixed in:
- 1.0.22
- Disclosed:
- Nov 11, 2025
CVE-2024-5020 on NVD →
Thumbnail Slider With Lightbox [wp-responsive-slider-with-lightbox] < 1.0.5
unknown
[en] The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticat...
- Affected:
- up to 1.0.5
- Fixed in:
- 1.0.5
- Disclosed:
- Oct 29, 2025
CVE-2015-10146 on NVD →
Thumbnail Slider With Lightbox <= 1.0.4 - Authenticated (Admin+) SQL Injection
medium
The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated at...
- CVSS:
- 4.9
- Affected:
- up to 1.0.4
- Fixed in:
- 1.0.5
- Disclosed:
- Oct 28, 2025
CVE-2015-10146 on NVD →
Thumbnail Slider With Lightbox [wp-responsive-slider-with-lightbox] < 1.0.1
unknown
[en] The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the addedit functionality. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged request granted they can...
- Affected:
- up to 1.0.1
- Fixed in:
- 1.0.1
- Disclosed:
- Oct 27, 2023
CVE-2023-5820 on NVD →
Thumbnail Slider With Lightbox <= 1.0 - Cross-Site Request Forgery to Arbitrary File Upload
high
The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the addedit functionality. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged request granted they can tric...
- CVSS:
- 8.3
- Affected:
- 1.0 – 1.0
- Fixed in:
- 1.0.1
- Disclosed:
- Oct 26, 2023
CVE-2023-5820 on NVD →
Thumbnail Slider With Lightbox [wp-responsive-slider-with-lightbox] < 1.0.1
unknown
[en] The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Title field in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to in...
- Affected:
- up to 1.0.1
- Fixed in:
- 1.0.1
- Disclosed:
- Oct 18, 2023
CVE-2023-5621 on NVD →
Thumbnail Slider With Lightbox <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via Image Title
medium
The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Title field in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject...
- CVSS:
- 4.4
- Affected:
- up to 1.0
- Fixed in:
- 1.0.1
- Disclosed:
- Oct 17, 2023
CVE-2023-5621 on NVD →
Thumbnail Slider With Lightbox [wp-responsive-slider-with-lightbox] < 1.0.1
unknown
[en] The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the delete functionality. This makes it possible for unauthenticated attackers to delete image lightboxes via a forged r...
- Affected:
- up to 1.0.1
- Fixed in:
- 1.0.1
- Disclosed:
- Oct 12, 2023
CVE-2023-5531 on NVD →
Thumbnail Slider With Lightbox <= 1.0 - Cross-Site Request Forgery
medium
The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the delete functionality. This makes it possible for unauthenticated attackers to delete image lightboxes via a forged reques...
- CVSS:
- 4.3
- Affected:
- up to 1.0
- Fixed in:
- 1.0.1
- Disclosed:
- Oct 11, 2023
CVE-2023-5531 on NVD →
Thumbnail Slider With Lightbox <= 1.0.17 - Reflected Cross-Site Scripting
high
The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_term’ parameter in versions up to, and including, 1.0.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web script...
- CVSS:
- 8.2
- Affected:
- up to 1.0.17
- Fixed in:
- 1.0.18
- Disclosed:
- Apr 25, 2023
Thumbnail Slider With Lightbox [wp-responsive-slider-with-lightbox] < 1.0.18
unknown
The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_term’ parameter in versions up to, and including, 1.0.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web script...
- Affected:
- up to 1.0.18
- Fixed in:
- 1.0.18
- Disclosed:
- Apr 25, 2023
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database