Medium 5.3
2025-07-04< 3.8
CVE-2025-24748
Minimum safe version
3.8
Update to 3.8 or later to address 4 fixable vulnerabilities
CVE-2025-24748
WordPress All In One Slider Responsive Plugin <= 3.7.9 is vulnerable to SQL Injection
All In One Slider <= 1.2.20 - Reflected Cross-Site Scripting
all_in_one_carousel 1.2.20 - /tpl/add_carousel.php id Parameter Reflected XSS
WordPress All In One Carousel Plugin <= 1.2.20 - Reflected XSS