| CVE-2025-60109 | WordPress LambertGroup - AllInOne - Content Slider Plugin <= 3.8 - SQL Injection Vulnerability | LambertGroup | LambertGroup - AllInOne - Content Slider | High | 8.5 | 2025-09-26 08:31:27 | Deep Dive |
| CVE-2025-57955 | WordPress Post Carousel Slider for Elementor Plugin <= 1.7.0 - Broken Access Control Vulnerability | Plugin Devs | Post Carousel Slider for Elementor | Medium | 6.5 | 2025-09-22 18:24:48 | Deep Dive |
| CVE-2025-58025 | WordPress Master Slider Plugin <= 3.11.0 - Cross Site Scripting (XSS) Vulnerability | averta | Master Slider | Medium | 6.5 | 2025-09-22 18:23:58 | Deep Dive |
| CVE-2025-58676 | WordPress HORIZONTAL SLIDER Plugin <= 2.4 - Cross Site Request Forgery (CSRF) Vulnerability | extendyourweb | HORIZONTAL SLIDER | High | 7.1 | 2025-09-22 18:22:51 | Deep Dive |
| CVE-2025-8481 | Blog Designer For Elementor – Post Slider, Post Carousel, Post Grid <= 1.1.7 - Cross-Site Request Forgery | mdimran41 | Blog Designer For Elementor – Post Slider, Post Carousel, Post Grid | Medium | 4.3 | 2025-09-11 07:24:58 | Deep Dive |
| CVE-2025-58882 | WordPress Simple Text Slider Plugin <= 1.0.5 - Cross Site Scripting (XSS) Vulnerability | w1zzard | Simple Text Slider | Medium | 6.5 | 2025-09-05 13:45:52 | Deep Dive |
| CVE-2025-58816 | WordPress Product Carousel Slider for Elementor Plugin <= 2.1.3 - Broken Access Control Vulnerability | Plugin Devs | Product Carousel Slider for Elementor | Low | 3.5 | 2025-09-05 13:45:16 | Deep Dive |
| CVE-2025-9217 | Slider Revolution <= 6.7.36 - Authenticated (Contributor+) Arbitrary File Read via 'used_svg' and 'used_images' | Revolution Slider | Slider Revolution | Medium | 6.5 | 2025-08-29 10:54:03 | Deep Dive |
| CVE-2025-54734 | WordPress B Slider Plugin <= 1.1.30 - Broken Access Control Vulnerability | bPlugins | B Slider | Medium | 5.8 | 2025-08-28 12:37:39 | Deep Dive |
| CVE-2025-58216 | WordPress WP Thumbtack Review Slider Plugin <= 2.6 - Cross Site Scripting (XSS) Vulnerability | jgwhite33 | WP Thumbtack Review Slider | Medium | 5.9 | 2025-08-27 17:45:50 | Deep Dive |
| CVE-2025-48154 | WordPress Multimedia Playlist Slider Addon for WPBakery Page Builder Plugin <= 2.1 - Cross Site Scripting (XSS) Vulnerability | LambertGroup | Multimedia Playlist Slider Addon for WPBakery Page Builder | High | 7.1 | 2025-08-20 08:03:32 | Deep Dive |
| CVE-2025-48159 | WordPress Youtube Vimeo Video Player and Slider WP Plugin <= 3.8 - Cross Site Scripting (XSS) Vulnerability | LambertGroup | Youtube Vimeo Video Player and Slider WP Plugin | High | 7.1 | 2025-08-20 08:03:30 | Deep Dive |
| CVE-2025-53563 | WordPress Youtube Vimeo Video Player and Slider <= 3.8 - Cross Site Scripting (XSS) Vulnerability | LambertGroup | Youtube Vimeo Video Player and Slider | High | 7.1 | 2025-08-20 08:03:13 | Deep Dive |
| CVE-2025-8676 | B Slider - Gutenberg Slider Block for WP <= 2.0.0 - Authenticated (Subscriber+) Sensitive Information Exposure | bplugins | bSlider – Create Responsive Image, Post, Product, and Video Sliders | Medium | 4.3 | 2025-08-15 02:24:24 | Deep Dive |
| CVE-2025-8680 | B Slider - Gutenberg Slider Block for WP <= 2.0.0 - Authenticated (Subscriber+) Server-Side Request Forgery | bplugins | bSlider – Create Responsive Image, Post, Product, and Video Sliders | Medium | 4.3 | 2025-08-15 02:24:23 | Deep Dive |
| CVE-2025-30626 | WordPress Multimedia Playlist Slider Addon for WPBakery Page Builder <= 2.1 - Cross Site Scripting (XSS) Vulnerability | LambertGroup | Multimedia Playlist Slider Addon for WPBakery Page Builder | High | 7.1 | 2025-08-14 10:34:31 | Deep Dive |
| CVE-2025-8418 | B Slider- Gutenberg Slider Block for WP <= 1.1.30 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Plugin Installation | bplugins | bSlider – Create Responsive Image, Post, Product, and Video Sliders | High | 8.8 | 2025-08-12 06:42:42 | Deep Dive |
| CVE-2025-8690 | Simple Responsive Slider <= 2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | addix | Simple Responsive Slider | Medium | 6.4 | 2025-08-12 02:24:47 | Deep Dive |
| CVE-2025-6228 | Sina Extension for Elementor <= 3.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via `Sina Posts`, `Sina Blog Post` and `Sina Table` Widgets | shaonsina | Sina Extension for Elementor | Medium | 6.4 | 2025-08-01 11:18:56 | Deep Dive |
| CVE-2025-6348 | Smart Slider 3 <= 3.5.1.28 - Authenticated (Administrator+) SQL Injection via `sliderid` Parameter | nextendweb | Smart Slider 3 | Medium | 4.9 | 2025-07-30 08:23:02 | Deep Dive |