| CVE-2024-2006 | Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.7 - Authenticated (Contributor+) PHP Object Injection in outpost_shortcode_metabox_markup | wpwax | Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget | High | 8.8 | 2024-03-13 15:27:04 | Deep Dive |
| CVE-2024-1507 | Prime Slider – Addons For Elementor <= 3.13.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Rubix Widget | bdthemes | Prime Slider – Addons for Elementor | Medium | 6.4 | 2024-03-13 13:52:12 | Deep Dive |
| CVE-2024-1508 | Prime Slider – Addons For Elementor <= 3.13.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Mercury Widget | bdthemes | Prime Slider – Addons for Elementor | Medium | 6.4 | 2024-03-13 13:52:12 | Deep Dive |
| CVE-2015-10130 | WordPress Plugin Team Circle Image Slider With Lightbox 安全漏洞 | nik00726 | Team Circle Image Slider With Lightbox | Medium | 5.3 | 2024-03-13 02:34:52 | Deep Dive |
| CVE-2024-1506 | Prime Slider – Addons For Elementor <= 3.13.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Fiestar Widget | bdthemes | Prime Slider – Addons for Elementor | Medium | 6.4 | 2024-03-07 06:59:45 | Deep Dive |
| CVE-2024-0611 | Master Slider – Responsive Touch Slider <= 3.9.9 - Authenticated(Editor+) Stored Cross-Site Scripting via slider callback | averta | Master Slider – Responsive Touch Slider | Medium | 4.4 | 2024-03-02 11:15:35 | Deep Dive |
| CVE-2024-1449 | Master Slider – Responsive Touch Slider <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting | averta | Master Slider – Responsive Touch Slider | Medium | 6.4 | 2024-03-02 11:15:35 | Deep Dive |
| CVE-2023-6326 | Master Slider - Responsive Touch Slider <= 3.9.10 - Cross-Site Request Forgery via process_bulk_action | averta | Master Slider – Responsive Touch Slider | Medium | 5.4 | 2024-03-02 11:15:34 | Deep Dive |
| CVE-2024-1859 | Slider Responsive Slideshow – Image slider, Gallery slideshow <= 1.3.8 - Authenticated (Contributor+) PHP Object Injection | awordpresslife | Responsive Slideshow | High | 8.8 | 2024-03-01 06:47:51 | Deep Dive |
| CVE-2023-51530 | WordPress GS Logo Slider Plugin <= 3.5.1 is vulnerable to Cross Site Request Forgery (CSRF) | GS Plugins | Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation | Medium | 4.3 | 2024-02-29 04:49:09 | Deep Dive |
| CVE-2024-24931 | WordPress Before After Image Slider WP Plugin <= 2.2 is vulnerable to Cross Site Scripting (XSS) | swadeshswain | Before After Image Slider WP | Medium | 6.5 | 2024-02-12 05:52:26 | Deep Dive |
| CVE-2024-24801 | WordPress OWL Carousel Plugin <= 1.4.0 is vulnerable to Cross Site Scripting (XSS) | LogicHunt | OWL Carousel – WordPress Owl Carousel Slider | Medium | 6.5 | 2024-02-10 07:53:37 | Deep Dive |
| CVE-2024-24877 | WordPress Wonder Slider Lite Plugin <= 13.9 is vulnerable to Cross Site Scripting (XSS) | Magic Hills Pty Ltd | Wonder Slider Lite | High | 7.1 | 2024-02-08 13:02:00 | Deep Dive |
| CVE-2024-0612 | Content Views <= 3.6.2 - Authenticated(Administrator+) Stored Cross-Site Scripting via settings | pt-guy | Content Views – Post Grid & Filter, Recent Posts, Category Posts … (Shortcode, Gutenberg Blocks, and Widgets for Elementor) | Medium | 4.4 | 2024-02-05 21:21:57 | Deep Dive |
| CVE-2023-51685 | WordPress WP Review Slider Plugin <= 12.7 is vulnerable to Cross Site Scripting (XSS) | LJ Apps | WP Review Slider | Medium | 5.9 | 2024-02-01 10:37:08 | Deep Dive |
| CVE-2024-22286 | WordPress BA Plus Plugin <= 1.0.3 is vulnerable to Cross Site Scripting (XSS) | Aluka | BA Plus – Before & After Image Slider FREE | High | 7.1 | 2024-01-31 17:52:08 | Deep Dive |
| CVE-2024-22295 | WordPress Robo Gallery Plugin <= 3.2.17 is vulnerable to Cross Site Scripting (XSS) | RoboSoft | Photo Gallery, Images, Slider in Rbs Image Gallery | Medium | 5.9 | 2024-01-31 17:30:41 | Deep Dive |
| CVE-2023-6456 | WP Review Slider < 13.0 - Admin+ Stored XSS | Unknown | WP Review Slider | 中危 | - | 2024-01-22 19:14:28 | Deep Dive |
| CVE-2022-45845 | WordPress Smart Slider 3 Plugin <= 3.5.1.9 is vulnerable to PHP Object Injection | Nextend | Smart Slider 3 | Medium | 4.3 | 2024-01-19 14:42:11 | Deep Dive |
| CVE-2023-6528 | Slider Revolution < 6.6.19 - Author+ Insecure Deserialization leading to RCE | Unknown | Slider Revolution | - | - | 2024-01-08 19:00:35 | Deep Dive |