plugin

Wp Responsive Slider With Lightbox Vulnerabilities

11 known security issues reported for the Wp Responsive Slider With Lightbox WordPress plugin. Most recent disclosed Nov 11, 2025.

2 high 4 medium

Running Wp Responsive Slider With Lightbox on your site? Check whether your installed version is affected.

Scan your site free

Thumbnail Slider With Lightbox <= 1.0.21 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

medium

The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FancyBox in all versions up to, and including, 1.0.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to injec...

CVSS:
6.4
Affected:
up to 1.0.21
Fixed in:
1.0.22
Disclosed:
Nov 11, 2025

CVE-2024-5020 on NVD →

Thumbnail Slider With Lightbox [wp-responsive-slider-with-lightbox] < 1.0.5

unknown

[en] The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticat...

Affected:
up to 1.0.5
Fixed in:
1.0.5
Disclosed:
Oct 29, 2025

CVE-2015-10146 on NVD →

Thumbnail Slider With Lightbox <= 1.0.4 - Authenticated (Admin+) SQL Injection

medium

The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated at...

CVSS:
4.9
Affected:
up to 1.0.4
Fixed in:
1.0.5
Disclosed:
Oct 28, 2025

CVE-2015-10146 on NVD →

Thumbnail Slider With Lightbox [wp-responsive-slider-with-lightbox] < 1.0.1

unknown

[en] The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the addedit functionality. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged request granted they can...

Affected:
up to 1.0.1
Fixed in:
1.0.1
Disclosed:
Oct 27, 2023

CVE-2023-5820 on NVD →

Thumbnail Slider With Lightbox <= 1.0 - Cross-Site Request Forgery to Arbitrary File Upload

high

The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the addedit functionality. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged request granted they can tric...

CVSS:
8.3
Affected:
1.0 – 1.0
Fixed in:
1.0.1
Disclosed:
Oct 26, 2023

CVE-2023-5820 on NVD →

Thumbnail Slider With Lightbox [wp-responsive-slider-with-lightbox] < 1.0.1

unknown

[en] The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Title field in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to in...

Affected:
up to 1.0.1
Fixed in:
1.0.1
Disclosed:
Oct 18, 2023

CVE-2023-5621 on NVD →

Thumbnail Slider With Lightbox <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via Image Title

medium

The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Title field in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject...

CVSS:
4.4
Affected:
up to 1.0
Fixed in:
1.0.1
Disclosed:
Oct 17, 2023

CVE-2023-5621 on NVD →

Thumbnail Slider With Lightbox [wp-responsive-slider-with-lightbox] < 1.0.1

unknown

[en] The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the delete functionality. This makes it possible for unauthenticated attackers to delete image lightboxes via a forged r...

Affected:
up to 1.0.1
Fixed in:
1.0.1
Disclosed:
Oct 12, 2023

CVE-2023-5531 on NVD →

Thumbnail Slider With Lightbox <= 1.0 - Cross-Site Request Forgery

medium

The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the delete functionality. This makes it possible for unauthenticated attackers to delete image lightboxes via a forged reques...

CVSS:
4.3
Affected:
up to 1.0
Fixed in:
1.0.1
Disclosed:
Oct 11, 2023

CVE-2023-5531 on NVD →

Thumbnail Slider With Lightbox <= 1.0.17 - Reflected Cross-Site Scripting

high

The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_term’ parameter in versions up to, and including, 1.0.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web script...

CVSS:
8.2
Affected:
up to 1.0.17
Fixed in:
1.0.18
Disclosed:
Apr 25, 2023

Thumbnail Slider With Lightbox [wp-responsive-slider-with-lightbox] < 1.0.18

unknown

The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_term’ parameter in versions up to, and including, 1.0.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web script...

Affected:
up to 1.0.18
Fixed in:
1.0.18
Disclosed:
Apr 25, 2023

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database