| CVE-2026-4076 | Slider Bootstrap Carousel <= 1.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes | felipermendes | Slider Bootstrap Carousel | Medium | 6.4 | 2026-04-22 07:45:33 | Deep Dive |
| CVE-2026-39467 | WordPress Responsive Slider by MetaSlider plugin <= 3.106.0 - PHP Object Injection vulnerability | MetaSlider | Responsive Slider by MetaSlider | High | 7.2 | 2026-04-21 09:35:29 | Deep Dive |
| CVE-2026-6443 | Essentialplugin Plugins (Various Versions) - Injected Backdoor | essentialplugin | Accordion and Accordion Slider | Critical | 9.8 | 2026-04-17 06:44:49 | Deep Dive |
| CVE-2026-5694 | Quick Interest Slider <= 3.1.5 - Unauthenticated Stored Cross-Site Scripting | aerin | Quick Interest Slider | High | 7.2 | 2026-04-15 07:45:30 | Deep Dive |
| CVE-2026-3017 | Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts <= 3.0.12 - Authenticated (Administrator+) PHP Object Injection | shapedplugin | Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts | High | 7.2 | 2026-04-14 05:30:33 | Deep Dive |
| CVE-2026-34424 | Smart Slider 3 Pro 3.5.1.35 Supply Chain Attack Remote Access Toolkit | Nextendweb | Smart Slider 3 Pro for WordPress | Critical | 9.8 | 2026-04-09 22:59:38 | Deep Dive |
| CVE-2026-4300 | Robo Gallery <= 5.1.3 - Authenticated (Author+) Stored Cross-Site Scripting via 'Loading Label' Setting | robosoft | Robo Gallery – Photo & Image Slider | Medium | 6.4 | 2026-04-08 09:25:50 | Deep Dive |
| CVE-2026-4341 | Prime Slider <= 4.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'follow_us_text' Parameter | bdthemes | Prime Slider – Addons for Elementor | Medium | 6.4 | 2026-04-08 03:36:09 | Deep Dive |
| CVE-2026-4065 | Smart Slider 3 <= 3.5.1.33 - Missing Authorization to Authenticated (Contributor+) Slider Data Read and Image Record Manipulation | nextendweb | Smart Slider 3 | Medium | 5.4 | 2026-04-07 21:26:20 | Deep Dive |
| CVE-2026-3098 | Smart Slider 3 <= 3.5.1.33 - Authenticated (Subscriber+) Arbitrary File Read via actionExportAll | nextendweb | Smart Slider 3 | Medium | 6.5 | 2026-03-27 03:37:08 | Deep Dive |
| CVE-2026-32491 | WordPress WP Review Slider plugin <= 13.9 - Cross Site Scripting (XSS) vulnerability | jgwhite33 | WP Review Slider | 中危 | - | 2026-03-25 16:14:59 | Deep Dive |
| CVE-2026-32490 | WordPress WP TripAdvisor Review Slider plugin <= 14.1 - Cross Site Scripting (XSS) vulnerability | jgwhite33 | WP TripAdvisor Review Slider | 中危 | - | 2026-03-25 16:14:59 | Deep Dive |
| CVE-2026-32494 | WordPress Image Slider by Ays plugin <= 2.7.1 - Cross Site Scripting (XSS) vulnerability | Ays Pro | Image Slider by Ays | 中危 | - | 2026-03-25 16:14:59 | Deep Dive |
| CVE-2026-25455 | WordPress Product Slider for WooCommerce plugin <= 1.13.61 - Broken Access Control vulnerability | PickPlugins | Product Slider for WooCommerce | Medium | 6.5 | 2026-03-25 16:14:50 | Deep Dive |
| CVE-2026-0609 | Logo Slider <= 4.9.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'logo-slider' Shortcode | logichunt | Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider Plugin | Medium | 6.4 | 2026-03-21 03:27:01 | Deep Dive |
| CVE-2026-3331 | Lobot Slider Administrator <= 0.6.0 - Cross-Site Request Forgery to Settings Update | chuckmo | Lobot Slider Administrator | Medium | 4.3 | 2026-03-21 03:26:53 | Deep Dive |
| CVE-2026-1899 | Any Post Slider <= 1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'post_type' Shortcode Attribute | itpathsolutions | Any Post Slider | Medium | 6.4 | 2026-03-21 03:26:47 | Deep Dive |
| CVE-2026-32402 | WordPress Image Slider by Ays plugin <= 2.7.1 - Broken Access Control vulnerability | Ays Pro | Image Slider by Ays | 中危 | - | 2026-03-13 11:42:13 | Deep Dive |
| CVE-2026-28109 | WordPress LambertGroup - AllInOne - Content Slider plugin <= 3.8 - Reflected Cross Site Scripting (XSS) vulnerability | LambertGroup | LambertGroup - AllInOne - Content Slider | 中危 | - | 2026-03-05 05:54:27 | Deep Dive |
| CVE-2026-22346 | WordPress Slider Responsive Slideshow – Image slider, Gallery slideshow plugin <= 1.5.4 - PHP Object Injection vulnerability | A WP Life | Slider Responsive Slideshow – Image slider, Gallery slideshow | - | - | 2026-02-20 15:47:00 | Deep Dive |