Extension WordPress

Vulnérabilités Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

Cette page rassemble les failles publiées pour Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider, leurs plages de versions affectées et les correctifs signalés dans la base locale.

15Vulnérabilités
0Critiques
15Avec correctif
7,2CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

15 fiches

CVE-2026-39465 Élevée · 7,2
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider <= 3.106.0 – Authenticated (Editor+) Remote Code Execution

The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.106.0. This makes it possible for authenticated attackers, with Editor-level…

Versions affectées

*-3.106.0

Correctif

3.107.0

Publication

20/04/2026

CVE-2026-39467 Moyenne · 6,6
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider <= 3.106.0 – Authenticated (Editor+) PHP Object Injection

The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.106.0 via deserialization of untrusted input. This makes it possible for…

Versions affectées

*-3.106.0

Correctif

3.107.0

Publication

20/04/2026

CVE-2025-5337 Moyenne · 6,4
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

Slider, Gallery, and Carousel by MetaSlider <= 3.98.0 – Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via aria-label Parameter

The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘aria-label’ parameter in all versions up to, and including, 3.98.0 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-3.98.0

Correctif

3.99.0

Publication

13/06/2025

CVE-2025-1062 Moyenne · 4,4
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider <= 3.94.0 – Authenticated (Admin+) Stored Cross-Site Scripting

The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.94.0 due to insufficient input sanitization and…

Versions affectées

*-3.94.0

Correctif

3.95.0

Publication

02/03/2025

CVE-2025-1203 Moyenne · 4,4
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider <= 3.94.0 – Authenticated (Admin+) Stored Cross-Site Scripting

The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.94.0 due to insufficient input sanitization and…

Versions affectées

*-3.94.0

Correctif

3.95.0

Publication

02/03/2025

CVE-2025-26763 Élevée · 7,2
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider <= 3.94.0 – Authenticated (Editor+) PHP Object Injection

The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.94.0 via deserialization of untrusted input. This makes it possible…

Versions affectées

*-3.94.0

Correctif

3.95.0

Publication

14/02/2025

CVE-2025-24533 Moyenne · 4,3
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider <= 3.92.0 – Cross-Site Request Forgery

The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.92.0. This is due to missing or incorrect nonce validation…

Versions affectées

*-3.92.0

Correctif

3.92.1

Publication

09/11/2024

CVE-2024-3285 Moyenne · 6,4
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Slideshows <= 3.70.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via metaslider Shortcode

The Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Slideshows plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'metaslider' shortcode in all versions up to, and including, 3.70.0 due to insufficient input sanitization…

Versions affectées

*-3.70.0

Correctif

3.70.1

Publication

10/04/2024

CVE-2023-1473 Moyenne · 6,1
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

Slider, Gallery, and Carousel by MetaSlider <= 3.29.0 – Reflected Cross-Site Scripting

The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 3.29.0 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-3.29.0

Correctif

3.29.1

Publication

20/03/2023

Vulnérabilité Moyenne · 4,3
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

Appsero <= 1.2.1 – Missing Authorization

The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.1. This makes it possible…

Versions affectées

*-3.28.0

Correctif

3.28.1

Publication

16/12/2022

CVE-2022-47150 Moyenne · 4,3
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

Appsero <= 1.2.0 – Cross-Site Request Forgery

The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it…

Versions affectées

*-3.28.0

Correctif

3.28.1

Publication

14/12/2022

CVE-2022-2823 Moyenne · 5,5
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Plugin <= 3.27.8 – Authenticated (Administrator+) Stored Cross-Site Scripting

The "Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.27.8 due to insufficient input sanitization and output escaping of some of…

Versions affectées

3.27.8

Correctif

3.27.9

Publication

14/09/2022

Vulnérabilité Moyenne · 6,4
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

Slider, Gallery, and Carousel by MetaSlider <= 3.17.1 – Authenticated Stored Cross-Site Scripting

The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross Site Scripting in versions up to, and including, 3.17.1. The patch adds extra filtering of captions using HTML Purifier where there appeared to…

Versions affectées

[*, 3.17.2)

Correctif

3.17.2

Publication

28/08/2020

Vulnérabilité Moyenne · 5,3
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Plugin <= 2.1.6 – Full Path Disclosure

The Meta Slider plugin for WordPress is vulnerable to full path disclosure in versions up to, and including, 2.1.6. This makes it possible for unauthenticated attackers to discover the path of folders and files hosted on a vulnerable…

Versions affectées

*-2.1.6

Correctif

2.2

Publication

01/08/2014

CVE-2014-4846 Moyenne · 6,1
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Plugin <= 2.5 – Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in the Meta Slider (ml-slider) plugin 2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter to wp-admin/admin.php.

Versions affectées

*-2.5

Correctif

2.6

Publication

01/08/2014

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités