Browse all 5 CVE security advisories affecting metaslider. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Metaslider is a WordPress plugin for creating image sliders and carousels. Historically, it has been vulnerable to multiple security issues including cross-site scripting (XSS), remote code execution (RCE), and privilege escalation vulnerabilities. These flaws often stem from insufficient input validation and improper permission checks. The plugin has accumulated five CVEs to date, with some allowing unauthenticated attackers to execute arbitrary code or steal sensitive data. While no major public incidents have been widely documented, the consistent pattern of vulnerabilities suggests potential risks for unpatched installations, particularly those running outdated versions where these issues remain unaddressed.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-5337 | Slider, Gallery, and Carousel by MetaSlider <= 3.98.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via aria-label Parameter — Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video SliderCWE-79 | 6.4 | Medium | 2025-06-14 |
| CVE-2024-3285 | Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Slideshows <= 3.70.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via metaslider Shortcode — Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video SliderCWE-79 | 6.4 | Medium | 2024-04-11 |
This page lists every published CVE security advisory associated with metaslider. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.