| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-68000 | WordPress Testimonial Slider plugin <= 2.0.15 - Broken Access Control vulnerability | PickPlugins | Testimonial Slider | Medium | 6.5 | 2026-02-20 15:46:34 | Deep Dive |
| CVE-2026-2716 | Client Testimonial Slider <= 2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Testimonial Heading' Setting | amu02aftab | Client Testimonial Slider | Medium | 4.4 | 2026-02-19 09:26:36 | Deep Dive |
| CVE-2026-25399 | WordPress Serious Slider plugin <= 1.2.7 - Broken Access Control vulnerability | CryoutCreations | Serious Slider | - | - | 2026-02-19 08:27:04 | Deep Dive |
| CVE-2026-1405 | Slider Future <= 1.0.5 - Unauthenticated Arbitrary File Upload | franchidesign | Slider Future | Critical | 9.8 | 2026-02-19 04:36:09 | Deep Dive |
| CVE-2026-1988 | Flexi Product Slider and Grid for WooCommerce <= 1.0.5 - Authenticated (Contributor+) Local File Inclusion via 'theme' Shortcode Attribute | wpdecent | Flexi Product Slider and Grid for WooCommerce | High | 7.5 | 2026-02-14 06:42:38 | Deep Dive |
| CVE-2026-0727 | Accordion and Accordion Slider <= 1.4.5 - Missing Authorization to Authenticated (Contributor+) Attachment Metadata Modification | essentialplugin | Accordion and Accordion Slider | Medium | 5.4 | 2026-02-14 06:42:26 | Deep Dive |
| CVE-2026-1634 | Subitem AL Slider <= 1.0.0 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] | alexdtn | Subitem AL Slider | Medium | 6.1 | 2026-02-07 08:26:38 | Deep Dive |
| CVE-2026-24626 | WordPress Logo Slider plugin <= 5.1.1 - Cross Site Scripting (XSS) vulnerability | LogicHunt | Logo Slider | Medium | 5.9 | 2026-01-23 14:29:08 | Deep Dive |
| CVE-2026-24383 | WordPress B Slider plugin <= 2.0.6 - Cross Site Scripting (XSS) vulnerability | bPlugins | B Slider | - | - | 2026-01-22 16:52:47 | Deep Dive |
| CVE-2026-22347 | WordPress Carousel Horizontal Posts Content Slider plugin <= 3.3.2 - Cross Site Scripting (XSS) vulnerability | subhansanjaya | Carousel Horizontal Posts Content Slider | - | - | 2026-01-22 16:52:34 | Deep Dive |
| CVE-2025-68558 | WordPress Depicter Slider plugin <= 4.0.4 - Broken Access Control vulnerability | averta | Depicter Slider | Medium | 6.5 | 2026-01-22 16:52:09 | Deep Dive |
| CVE-2025-68009 | WordPress Slider Templates plugin <= 1.0.3 - Broken Access Control vulnerability | Codeless | Slider Templates | Medium | 6.5 | 2026-01-22 16:52:01 | Deep Dive |
| CVE-2025-49066 | WordPress Accordion Slider PRO plugin <= 1.2 - Reflected Cross Site Scripting (XSS) vulnerability | LambertGroup | Accordion Slider PRO | High | 7.1 | 2026-01-22 16:51:43 | Deep Dive |
| CVE-2025-49043 | WordPress Magic Responsive Slider and Carousel WordPress plugin <= 1.6 - Reflected Cross Site Scripting (XSS) vulnerability | LambertGroup | Magic Responsive Slider and Carousel WordPress | High | 7.1 | 2026-01-22 16:51:41 | Deep Dive |
| CVE-2025-48094 | WordPress Magic Slider plugin <= 2.2 - Reflected Cross Site Scripting (XSS) vulnerability | LambertGroup | Magic Slider | High | 7.1 | 2026-01-22 16:51:41 | Deep Dive |
| CVE-2026-0635 | Responsive Accordion Slider <= 1.2.2 - Missing Authorization to Authenticated (Contributor+) Slider Update via 'resp_accordion_silder_save_images' | techknowprime | Responsive Accordion Slider | Medium | 4.3 | 2026-01-14 05:28:09 | Deep Dive |
| CVE-2026-0680 | Real Post Slider Lite <= 2.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via Settings | vk011 | Real Post Slider Lite | Medium | 4.4 | 2026-01-14 05:28:06 | Deep Dive |
| CVE-2025-13897 | Client Testimonial Slider <= 2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'aft_testimonial_meta_name' Metabox Field | amu02aftab | Client Testimonial Slider | Medium | 6.4 | 2026-01-09 11:15:33 | Deep Dive |
| CVE-2026-22489 | WordPress Image Slider Slideshow plugin <= 1.8 - Insecure Direct Object References (IDOR) vulnerability | Wptexture | Image Slider Slideshow | Medium | 4.3 | 2026-01-08 16:33:34 | Deep Dive |
| CVE-2026-22522 | WordPress Block Slider plugin <= 2.2.3 - Broken Access Control vulnerability | Munir Kamal | Block Slider | Medium | 6.5 | 2026-01-08 16:17:03 | Deep Dive |