Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

Vulnerabilities 20Slug ml-sliderLatest version 3.109.0WordPress.org →

Minimum safe version

3.107.0

Update to 3.107.0 or later to address 20 fixable vulnerabilities

Latest available3.109.0
N/A
2026-04-20< 3.107.0

Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider <= 3.106.0 - Authenticated (Editor+) Remote Code Execution

Medium 5.4
2025-06-13< 3.99.0

Slider, Gallery, and Carousel by MetaSlider <= 3.98.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via aria-label Parameter

Low 3.5
2025-03-24< 3.95.0

Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider <= 3.94.0 - Authenticated (Admin+) Stored Cross-Site Scripting

Low 3.5
2025-03-24< 3.95.0

Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider <= 3.94.0 - Authenticated (Admin+) Stored Cross-Site Scripting

Medium 5.4
2024-04-15< 3.70.1

WordPress Responsive Slider by MetaSlider Plugin <= 3.70.0 is vulnerable to Cross Site Scripting (XSS)

N/A
< 2.2

Meta Slider 2.1.6 - Multiple Full Path Disclosure

N/A
< 3.17.2

MetaSlider &lt; 3.17.2 - Authenticated Stored Cross-Site Scripting (XSS)

N/A
2023-03-22< 3.29.1

WordPress Meta Slider Plugin <= 3.29.0 is vulnerable to Cross Site Scripting (XSS)

N/A
2023-03-21< 3.28.1

WordPress Responsive Slider by MetaSlider Plugin <= 3.28.0 is vulnerable to Cross Site Request Forgery (CSRF)

N/A
2023-03-20< 3.29.1

Slider, Gallery, and Carousel by MetaSlider <= 3.29.0 - Reflected Cross-Site Scripting

N/A
2014-08-01< 2.2

Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Plugin <= 2.1.6 - Full Path Disclosure

N/A
2020-08-28< 3.17.2

Slider, Gallery, and Carousel by MetaSlider <= 3.17.1 - Authenticated Stored Cross-Site Scripting

Medium 4.8
2023-09-14< 3.27.9

WordPress Responsive Slider by MetaSlider Plugin <= 3.27.8 is vulnerable to Cross Site Scripting (XSS)

N/A
2015-10-27< 2.2

WordPress Meta Slider Plugin <= 2.1.6 - Full Path Disclosure

N/A
2020-09-17< 3.17.2

WordPress Responsive Slider by MetaSlider plugin <= 3.17.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability

N/A
2014-08-01< 2.6

Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Plugin <= 2.5 - Cross-Site Scripting