{"error":0,"message":null,"data":{"name":"Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider","plugin":"ml-slider","link":"https:\/\/wordpress.org\/plugins\/ml-slider\/","latest":"1789657980","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"d8771519e5cdbbf30c5ef3f45f69a0cb9a8f598b20c3956cddcf3f9aa221afd9","name":"Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 2.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2014-4846","name":"CVE-2014-4846","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2014-4846","description":"[en] Cross-site scripting (XSS) vulnerability in the Meta Slider (ml-slider) plugin 2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter to wp-admin\/admin.php.","date":"2014-07-10"},{"id":"0b877630a2741ecd203ff5973e224db42808e940","name":"WordPress  Meta Slider Plugin <= 2.5 - XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ml-slider\/vulnerability\/wordpress-meta-slider-plugin-2-5-xss","description":"Because of this vulnerability, the attackers can inject arbitrary web script or HTML via the \"id\" parameter to wp-admin\/admin.php.\nUpdate the plugin.","date":"2014-07-10"},{"id":"7c773aa4c68e3f02130a1ad94ed9f56f148a63b7","name":"Slider, Gallery, and Carousel by MetaSlider \u2013 Responsive WordPress Plugin <= 2.5 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ml-slider\/slider-gallery-and-carousel-by-metaslider-responsive-wordpress-plugin-25-cross-site-scripting","description":"Cross-site scripting (XSS) vulnerability in the Meta Slider (ml-slider) plugin 2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter to wp-admin\/admin.php.","date":"2014-08-01"},{"id":"d7daaa2c-72ec-443e-b096-2e174ef45995","name":"Meta Slider &lt;= 2.5 - Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/d7daaa2c-72ec-443e-b096-2e174ef45995","description":"The Responsive Slider by MetaSlider &ndash; Slider and Carousel Plugin for WordPress WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"cecf2653a8c9dbd6e228deb11d35a06f327a8c9e8f33112658044ec2fb732a00","name":"Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.17.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.17.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"db37be5c6273b7fbca2994a50a5bae946ab9debc","name":"WordPress Responsive Slider by MetaSlider plugin <= 3.17.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ml-slider\/vulnerability\/wordpress-responsive-slider-by-metaslider-plugin-3-17-1-authenticated-stored-cross-site-scripting-xss-vulnerability","description":"Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by Vishnupriya Ilango (Fortinet FortiGuard Labs) in WordPress Responsive Slider by MetaSlider plugin (versions <= 3.17.1).","date":"2020-09-17"}],"impact":[]},{"uuid":"44960f450a365ac50ae973abbd6472562845b634ffc23ac16d072454bd85fdbb","name":"Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 2.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"e6ff536041721a15fb67c2a2aa79733b7dc4814a","name":"WordPress Meta Slider Plugin <= 2.1.6 -  Full Path Disclosure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ml-slider\/vulnerability\/wordpress-meta-slider-plugin-2-1-6-full-path-disclosure","description":"This plugin is prone to a full path disclosure vulnerability.\nUpdate the plugin.","date":"2015-10-27"}],"impact":[]},{"uuid":"819e596bace966d055e2f6d337c25c28378ffbf6ed9d2ef79539bd0497f80edd","name":"Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.27.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.27.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-2823","name":"CVE-2022-2823","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-2823","description":"[en] The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.27.9 does not sanitise and escape some of its Gallery Image parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)","date":"2022-10-10"},{"id":"ea7a341f0cfa28f1a18f987c9956e15a2924a6b8","name":"Slider, Gallery, and Carousel by MetaSlider \u2013 Responsive WordPress Plugin <= 3.27.8 - Authenticated (Administrator+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ml-slider\/slider-gallery-and-carousel-by-metaslider-responsive-wordpress-plugin-3278-authenticated-administrator-stored-cross-site-scripting","description":"The \"Slider, Gallery, and Carousel by MetaSlider \u2013 Responsive WordPress Plugin\" plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.27.8 due to insufficient input sanitization and output escaping of some of its parameters. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2022-09-14"},{"id":"2b7566c02fb6915a56d81336d703cba2903f950c","name":"WordPress  Responsive Slider by MetaSlider Plugin  <= 3.27.8 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ml-slider\/vulnerability\/wordpress-slider-gallery-and-carousel-by-metaslider-plugin-3-27-8-auth-stored-cross-site-scripting-xss-vulnerability","description":"Update the WordPress Responsive Slider by MetaSlider plugin to the latest available version (at least 3.27.9).\nAnurag Bhoir discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Responsive Slider by MetaSlider Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.27.9.","date":"2023-09-14"},{"id":"c88c85b3-2830-4354-99fd-af6bce6bb4ef","name":"Slider, Gallery, and Carousel by MetaSlider &lt; 3.27.9 - Admin+ Stored Cross Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/c88c85b3-2830-4354-99fd-af6bce6bb4ef","description":"The plugin does not sanitise and escape some of its Gallery Image parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"c2a7d962906dfe9af63f80d400bf0759c8556d42f58fe740abe39dc762e0d4ea","name":"Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.17.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.17.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"9507b16394ebe9e6ca301dfc53534fa4863471a4","name":"Slider, Gallery, and Carousel by MetaSlider <= 3.17.1 - Authenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ml-slider\/slider-gallery-and-carousel-by-metaslider-3171-authenticated-stored-cross-site-scripting","description":"The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross Site Scripting in versions up to, and including, 3.17.1. The patch adds extra filtering of captions using HTML Purifier where there appeared to be a stored cross-site scripting vulnerability to accounts with sufficient privileges.","date":"2020-08-28"}],"impact":[]},{"uuid":"88e2f763eff6521fedb6cb2eeff3673084245eba343c3dd4fdb4d1ab1bf5954f","name":"Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 2.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"e899f0cb8405cfd436770c7b0952476c4154b99c","name":"Slider, Gallery, and Carousel by MetaSlider \u2013 Responsive WordPress Plugin <= 2.1.6 - Full Path Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ml-slider\/slider-gallery-and-carousel-by-metaslider-responsive-wordpress-plugin-216-full-path-disclosure","description":"The Meta Slider plugin for WordPress is vulnerable to full path disclosure in versions up to, and including, 2.1.6. This makes it possible for unauthenticated attackers to discover the path of folders and files hosted on a vulnerable system.","date":"2014-08-01"}],"impact":[]},{"uuid":"f41a75e358df59662942e5ecfdd3833a0d41483e00498f11f0120102a04e1504","name":"Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.29.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.29.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"47cffe4183ad23100c37289a218fe346e5af7c86","name":"Slider, Gallery, and Carousel by MetaSlider <= 3.29.0 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ml-slider\/slider-gallery-and-carousel-by-metaslider-3290-reflected-cross-site-scripting","description":"The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the \u2018page\u2019 parameter in versions up to, and including, 3.29.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2023-03-20"},{"id":"CVE-2023-1473","name":"CVE-2023-1473","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-1473","description":"[en] The Slider, Gallery, and Carousel by MetaSlider WordPress plugin 3.29.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin","date":"2023-04-17"},{"id":"12dd63fbc051db7fbec5c81f51e41d8caaf9a185","name":"WordPress  Meta Slider Plugin  <= 3.29.0 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ml-slider1\/vulnerability\/wordpress-responsive-wordpress-slideshows-plugin-3-29-0-reflected-xss-vulnerability","description":"Update the WordPress Meta Slider plugin to the latest available version (at least 3.29.1).\nErwan LR (WPScan) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Meta Slider Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.29.1.","date":"2023-04-12"},{"id":"a6e6c67b-7d9b-4fdb-8115-c33add7bfc3d","name":"Responsive WordPress Slideshows 3.29.0 - Reflected XSS","link":"https:\/\/wpscan.com\/vulnerability\/a6e6c67b-7d9b-4fdb-8115-c33add7bfc3d","description":"The plugin does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"680215156288fbd565ae2388e8d3719b339693d2dfabcf5c5308e8c9a1ff962b","name":"Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.28.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.28.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-47150","name":"CVE-2022-47150","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-47150","description":"[en] Cross-Site request forgery (CSRF) vulnerability in weDevs WooCommerce Conversion Tracking allows Cross Site Request Forgery.\n\nThis issue affects WooCommerce Conversion Tracking: from n\/a through 2.0.10.","date":"2026-06-11"},{"id":"8bcd61bf0d2d09de3c19982d4416947d347af3e6","name":"WordPress  Responsive Slider by MetaSlider Plugin  <= 3.28.0 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ml-slider\/vulnerability\/wordpress-slider-gallery-and-carousel-by-metaslider-responsive-wordpress-plugin-plugin-3-28-0-cross-site-request-forgery-csrf","description":"Update the WordPress Responsive Slider by MetaSlider plugin to the latest available version (at least 3.28.1).\nLana Codes discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Responsive Slider by MetaSlider Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 3.28.1.","date":"2023-03-21"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"l","i":"n","a":"n","score":"4.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:L\/I:N\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"6297d199469b7ee1b5dcf417402a1c28f0fffb6f0a41b6b3b6e108ff69bbc781","name":"Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.29.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.29.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"49240f72da5449e0485de70c9e41a1181f2df412","name":"WordPress  Meta Slider Plugin  <= 3.29.0 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ml-slider1\/vulnerability\/wordpress-slider-gallery-and-carousel-by-metaslider-plugin-3-29-0-reflected-cross-site-scripting-vulnerability","description":"Update the WordPress Meta Slider plugin to the latest available version (at least 3.29.1).\nWordFence discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Meta Slider Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.29.1.","date":"2023-03-22"}],"impact":[]},{"uuid":"33b1329fcd2797746adffbdfbbc39f7cd6e0df7235ca785ae21c65a99a31fccc","name":"Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.17.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.17.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"151ec256-7c21-40db-84cb-d8b68f5c4973","name":"MetaSlider &lt; 3.17.2 - Authenticated Stored Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/151ec256-7c21-40db-84cb-d8b68f5c4973","description":"Vishnupriya Ilango, from Fortinet&#039;s FortiGuard Lab, discovered a stored Cross-Site Scripting (XSS) vulnerability in Metaslider plugin (v3.17.1), which exists in Image caption or description parameter in the slide creation module.","date":null}],"impact":[]},{"uuid":"94f3332514f6e4e05ab1994a4086c572c89e3f981d97b4bd0292c9cb30e386c1","name":"Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 2.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"09890bbf-f385-4614-a91b-e52a71f55f4f","name":"Meta Slider 2.1.6 - Multiple Full Path Disclosure","link":"https:\/\/wpscan.com\/vulnerability\/09890bbf-f385-4614-a91b-e52a71f55f4f","description":"The Responsive Slider by MetaSlider &ndash; Slider and Carousel Plugin for WordPress WordPress plugin was affected by a Multiple Full Path Disclosure security vulnerability.","date":null}],"impact":[]},{"uuid":"0efb06bb7edca3f59da7e905a36caa21dc36a478b2dcb1fc9936773e07ba6690","name":"Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.70.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.70.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-3285","name":"CVE-2024-3285","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-3285","description":"[en] The Slider, Gallery, and Carousel by MetaSlider \u2013 Responsive WordPress Slideshows plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'metaslider' shortcode in all versions up to, and including, 3.70.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-11"},{"id":"302cbdf940bebbe9206a2668004763b003a63780","name":"Slider, Gallery, and Carousel by MetaSlider \u2013 Responsive WordPress Slideshows <= 3.70.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via metaslider Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ml-slider\/slider-gallery-and-carousel-by-metaslider-responsive-wordpress-slideshows-3700-authenticated-contributor-stored-cross-site-scripting-via-metaslider-shortcode","description":"The Slider, Gallery, and Carousel by MetaSlider \u2013 Responsive WordPress Slideshows plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'metaslider' shortcode in all versions up to, and including, 3.70.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-10"},{"id":"89770f89cd81ae348dce5942467ca47c8b5a0998","name":"WordPress Responsive Slider by MetaSlider Plugin <= 3.70.0 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ml-slider\/vulnerability\/wordpress-slider-gallery-and-carousel-by-metaslider-plugin-3-70-0-authenticated-contributor-stored-cross-site-scripting-via-metaslider-shortcode-vulnerability","description":"<p>WordPress Responsive Slider by MetaSlider Plugin <= 3.70.0 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Responsive Slider by MetaSlider<\/p><p>Link: https:\/\/wordpress.org\/plugins\/ml-slider\/#developers<\/p><p>Affected Version <= 3.70.0<\/p><p>Fixed in version 3.70.1 <\/p>","date":"2024-04-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"655ef512aec515d34008f6782c1ab07e1578ceb56ca4ab54a6969128a509f641","name":"Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.92.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.92.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-24533","name":"CVE-2025-24533","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-24533","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in MetaSlider Responsive Slider by MetaSlider ml-slider allows Cross Site Request Forgery.This issue affects Responsive Slider by MetaSlider: from n\/a through <= 3.92.0.","date":"2025-01-27"},{"id":"EUVD-2025-3745","name":"EUVD-2025-3745","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-3745","description":"Cross-Site Request Forgery (CSRF) vulnerability in MetaSlider Responsive Slider by MetaSlider allows Cross Site Request Forgery. This issue affects Responsive Slider by MetaSlider: from n\/a through 3.92.0.","date":"2025-01-27"},{"id":"1d966e471fe353040926eeb4f85788c6f4ff6273","name":"Slider, Gallery, and Carousel by MetaSlider \u2013 Image Slider, Video Slider  <= 3.92.0 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ml-slider\/slider-gallery-and-carousel-by-metaslider-image-slider-video-slider-3920-cross-site-request-forgery","description":"The Slider, Gallery, and Carousel by MetaSlider \u2013 Image Slider, Video Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.92.0. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action granted they can trick a site administrator into performing an action such as clicking on a link. The impact of this vulnerability is unknown.","date":"2024-11-09"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"l","score":"5.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"892758794b73b77c916dbceab6f613d9dac7cb0f06665f214aeb94773f131206","name":"Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.95.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.95.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-26763","name":"CVE-2025-26763","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-26763","description":"[en] Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider ml-slider allows Object Injection.This issue affects Responsive Slider by MetaSlider: from n\/a through <= 3.94.0.","date":"2025-02-22"},{"id":"7c0b7d2dc51178581443fec94eee33caaea570be","name":"WordPress Responsive Slider by MetaSlider Plugin <= 3.94.0 is vulnerable to PHP Object Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ml-slider\/vulnerability\/wordpress-slider-gallery-and-carousel-by-metaslider-image-slider-video-slider-plugin-3-94-0-php-object-injection-vulnerability","description":"<p>WordPress Responsive Slider by MetaSlider Plugin <= 3.94.0 is vulnerable to PHP Object Injection<\/p><p>Software: Responsive Slider by MetaSlider<\/p><p>Fixed in version 3.95.0 <\/p><p>Affected Version <= 3.94.0<\/p><p>CVE: CVE-2025-26763<\/p>","date":"2025-02-14"},{"id":"c7cbad8f31a87b0e3f0448930b4ac14c7ce66564","name":"Slider, Gallery, and Carousel by MetaSlider \u2013 Image Slider, Video Slider <= 3.94.0 - Authenticated (Editor+) PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ml-slider\/slider-gallery-and-carousel-by-metaslider-image-slider-video-slider-3940-authenticated-editor-php-object-injection","description":"The Slider, Gallery, and Carousel by MetaSlider \u2013 Image Slider, Video Slider plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.94.0 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.","date":"2025-02-14"},{"id":"EUVD-2025-4431","name":"EUVD-2025-4431","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-4431","description":"Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection. This issue affects Responsive Slider by MetaSlider: from n\/a through 3.94.0.","date":"2025-02-22"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-502","name":"Deserialization of Untrusted Data","description":"The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"8cd2410b03df9141626a4a97a97e65c58d28bde1f313be7cd30da6888a776ab2","name":"Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.95.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.95.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-1203","name":"Slider, Gallery, Carousel by MetaSlider < 3.95.0 - Editor+ Stored XSS","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-1203","description":"The Slider, Gallery, and Carousel by MetaSlider  WordPress plugin before 3.95.0 does not sanitise and escape some of its settings, which could allow high privilege users such as editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).","date":"0000-00-00"},{"id":"EUVD-2025-8002","name":"EUVD-2025-8002","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-8002","description":"The Slider, Gallery, and Carousel by MetaSlider  WordPress plugin before 3.95.0 does not sanitise and escape some of its settings, which could allow high privilege users such as editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).","date":"2025-03-24"},{"id":"a8ad5a078f076edcc5b5177234cdae1c55f0ff37","name":"Slider, Gallery, and Carousel by MetaSlider \u2013 Image Slider, Video Slider <= 3.94.0 - Authenticated (Admin+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ml-slider\/slider-gallery-and-carousel-by-metaslider-image-slider-video-slider-3940-authenticated-admin-stored-cross-site-scripting","description":"The Slider, Gallery, and Carousel by MetaSlider \u2013 Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.94.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2025-03-02"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:U\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"u","c":"l","i":"l","a":"n","score":"3.5","severity":"l","exploitable":"0.9","impact":"2.5"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:U\/C:L\/I:L\/A:N","score":"3.5","severity":"low","av":"network","ac":"low","pr":"high","ui":"required","s":"unchanged","c":"low","i":"low","a":"none","exploitable":"0.9","impact":"2.5"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"020a37b7837cd56c2cb2a276fa7cb0245ecfccb56df3ab344abea285ef897813","name":"Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.95.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.95.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-1062","name":"Slider, Gallery, Carousel by MetaSlider < 3.95.0 - Editor+ Stored XSS","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-1062","description":"The Slider, Gallery, and Carousel by MetaSlider  WordPress plugin before 3.95.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).","date":"0000-00-00"},{"id":"EUVD-2025-8000","name":"EUVD-2025-8000","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-8000","description":"The Slider, Gallery, and Carousel by MetaSlider  WordPress plugin before 3.95.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).","date":"2025-03-24"},{"id":"b8f7cdd19becf4771060bb83750d27c615a4cf69","name":"Slider, Gallery, and Carousel by MetaSlider \u2013 Image Slider, Video Slider <= 3.94.0 - Authenticated (Admin+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ml-slider\/slider-gallery-and-carousel-by-metaslider-image-slider-video-slider-3940-authenticated-admin-stored-cross-site-scripting-1","description":"The Slider, Gallery, and Carousel by MetaSlider \u2013 Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.94.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2025-03-02"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:U\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"u","c":"l","i":"l","a":"n","score":"3.5","severity":"l","exploitable":"0.9","impact":"2.5"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:U\/C:L\/I:L\/A:N","score":"3.5","severity":"low","av":"network","ac":"low","pr":"high","ui":"required","s":"unchanged","c":"low","i":"low","a":"none","exploitable":"0.9","impact":"2.5"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"d7cd087e4a7549147d309bb42c121f9fab1c81fdca52f7e2ea73435ba9d116a4","name":"Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.99.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.99.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-5337","name":"Slider, Gallery, and Carousel by MetaSlider <= 3.98.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via aria-label Parameter","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-5337","description":"The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018aria-label\u2019 parameter in all versions up to, and including, 3.98.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"243e4c3a0fcba0cd7c51d2c83ed6d86fc4734986","name":"Slider, Gallery, and Carousel by MetaSlider <= 3.98.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via aria-label Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ml-slider\/slider-gallery-and-carousel-by-metaslider-3980-authenticated-contributor-stored-dom-based-cross-site-scripting-via-aria-label-parameter","description":"The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018aria-label\u2019 parameter in all versions up to, and including, 3.98.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-06-13"},{"id":"EUVD-2025-18336","name":"EUVD-2025-18336","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-18336","description":"The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018aria-label\u2019 parameter in all versions up to, and including, 3.98.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-06-14"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"d5c3e074c6678cc7a11f5644e24f77f1a47c1a57d1b7e5b0847406e025be5598","name":"Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.107.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.107.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-39467","name":"CVE-2026-39467","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-39467","description":"[en] Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection.This issue affects Responsive Slider by MetaSlider: from n\/a through 3.106.0.","date":"2026-04-21"},{"id":"9cd650caf76586dd0c02842e31677192070f3fc7","name":"Slider, Gallery, and Carousel by MetaSlider \u2013 Image Slider, Video Slider <= 3.106.0 - Authenticated (Editor+) PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ml-slider\/slider-gallery-and-carousel-by-metaslider-image-slider-video-slider-31060-authenticated-editor-php-object-injection","description":"The Slider, Gallery, and Carousel by MetaSlider \u2013 Image Slider, Video Slider plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.106.0 via deserialization of untrusted input. This makes it possible for authenticated attackers, with editor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.","date":"2026-04-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"7.2","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.2","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-502","name":"Deserialization of Untrusted Data","description":"The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"8c5a6c57a1785f678d9be0b2c5c9a3b3c99d69bd06d13f7451210500ecb410fd","name":"Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.107.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.107.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-39465","name":"CVE-2026-39465","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-39465","description":"[en] Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider <= 3.106.0 versions.","date":"2026-06-15"},{"id":"b51d801c74cfdd9c0673be948b5fbdb0863c94db","name":"Slider, Gallery, and Carousel by MetaSlider \u2013 Image Slider, Video Slider <= 3.106.0 - Authenticated (Editor+) Remote Code Execution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ml-slider\/slider-gallery-and-carousel-by-metaslider-image-slider-video-slider-31060-authenticated-editor-remote-code-execution","description":"The Slider, Gallery, and Carousel by MetaSlider \u2013 Image Slider, Video Slider plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.106.0. This makes it possible for authenticated attackers, with Editor-level access and above, to execute code on the server.","date":"2026-04-20"},{"id":"EUVD-2026-36932","name":"EUVD-2026-36932","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-36932","description":"Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider <= 3.106.0 versions.","date":"2026-06-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"c","c":"h","i":"h","a":"h","score":"9.1","severity":"c","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:H\/I:H\/A:H","score":"9.1","severity":"critical","av":"network","ac":"low","pr":"high","ui":"none","s":"changed","c":"high","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-94","name":"Improper Control of Generation of Code ('Code Injection')","description":"The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"bcb858b37167c4e4609fd1992bbbc4e9886fc6a3101e9816775a21710ee9f70d","name":"Slider, Gallery, and Carousel by MetaSlider &#8211; Image Slider, Video Slider [ml-slider] < 3.111.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.111.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-18400","name":"CVE-2026-18400","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-18400","description":"[en] The Slider, Gallery, and Carousel by MetaSlider \u2013 Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'delay' Post Meta Setting in all versions up to, and including, 3.111.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The ml-slider custom post type is registered without custom capability restrictions and the ml-slider_settings meta key is unprotected, allowing Author-level users to set the malicious delay value via XML-RPC custom_fields when creating an ml-slider post.","date":"2026-08-06"},{"id":"3b4ff9201cc7e703f8d132b6ff75d4502427d60c","name":"Slider, Gallery, and Carousel by MetaSlider <= 3.111.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'delay' Post Meta Setting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/3f0082c6-c040-4244-be7b-b133fd24d093","description":"The Slider, Gallery, and Carousel by MetaSlider \u2013 Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'delay' Post Meta Setting in all versions up to, and including, 3.111.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The ml-slider custom post type is registered without custom capability restrictions and the ml-slider_settings meta key is unprotected, allowing Author-level users to set the malicious delay value via XML-RPC custom_fields when creating an ml-slider post.","date":"2026-08-05"},{"id":"e80b003d5cefb33b1313a67069046e46839b2ac5","name":"Slider, Gallery, and Carousel by MetaSlider <= 3.111.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'delay' Post Meta Setting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ml-slider\/slider-gallery-and-carousel-by-metaslider-31110-authenticated-author-stored-cross-site-scripting-via-delay-post-meta-setting","description":"The Slider, Gallery, and Carousel by MetaSlider \u2013 Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'delay' Post Meta Setting in all versions up to, and including, 3.111.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The ml-slider custom post type is registered without custom capability restrictions and the ml-slider_settings meta key is unprotected, allowing Author-level users to set the malicious delay value via XML-RPC custom_fields when creating an ml-slider post.","date":"2026-04-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1785997530"}