WordPress security by component
Master Slider
Plugin description
Master Slider is a WordPress component with 20 published CVE records in this archive. The latest tracked vulnerability was published Jun 25, 2026; the highest CVE/CNA score is 8.3.
Plugin slug:
master-sliderLatest vulnerability
CVE-2026-56014: Master Slider: Cross-site scripting
Master Slider is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.11.2.
| Safe version |
|
||
|---|---|---|---|
| Jun 25, 2026 |
CVE-2026-56014
Master Slider: Cross-site scripting
Master Slider is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.11.2.
|
> 3.11.2 |
CVE7.1
NVDPending
|
| May 27, 2026 |
CVE-2026-48968
Master Slider: Cross-site scripting
Master Slider is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.10.8.
|
3.10.9 |
CVE6.5
NVDPending
|
| Sep 22, 2025 |
CVE-2025-58025
Master Slider: Cross-site scripting
Master Slider is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Jun 17, 2025 |
CVE-2025-5291
Master Slider – Responsive Touch Slider: Cross-site scripting
Master Slider – Responsive Touch Slider is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 19, 2025 |
CVE-2025-39412
Master Slider: A security weakness
Master Slider is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Mar 05, 2025 |
CVE-2024-13757
Master Slider – Responsive Touch Slider: Cross-site scripting
Master Slider – Responsive Touch Slider is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 05, 2025 |
CVE-2024-11731
Master Slider – Responsive Touch Slider: Cross-site scripting
Master Slider – Responsive Touch Slider is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Feb 19, 2025 |
CVE-2024-12173
Master Slider: Cross-site scripting
Master Slider is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE3.5
NVDPending
|
| Jul 26, 2024 |
CVE-2024-6490
Master Slider: Cross-site request forgery
Master Slider is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jun 20, 2024 |
CVE-2024-37222
Master Slider: Cross-site scripting
Master Slider is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Jun 19, 2024 |
CVE-2023-50900
Master Slider: Cross-site request forgery
Master Slider is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Jun 18, 2024 |
CVE-2024-4375
Master Slider – Responsive Touch Slider: Cross-site scripting
Master Slider – Responsive Touch Slider is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jun 01, 2024 |
CVE-2023-6382
Master Slider – Responsive Touch Slider: Cross-site scripting
Master Slider – Responsive Touch Slider is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 21, 2024 |
CVE-2024-4470
Master Slider – Responsive Touch Slider: Cross-site scripting
Master Slider – Responsive Touch Slider is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 18, 2024 |
CVE-2024-32600
Master Slider: Code execution
Master Slider is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE8.3
NVD9.6
|
| Apr 18, 2024 |
CVE-2024-32580
Master Slider: Cross-site scripting
Master Slider is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Mar 02, 2024 |
CVE-2024-1449
Master Slider – Responsive Touch Slider: Cross-site scripting
Master Slider – Responsive Touch Slider is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 02, 2024 |
CVE-2024-0611
Master Slider – Responsive Touch Slider: Cross-site scripting
Master Slider – Responsive Touch Slider is affected by cross-site scripting. Exploitation requires at least editor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.4
NVD4.8
|
| Mar 02, 2024 |
CVE-2023-6326
Master Slider – Responsive Touch Slider: Cross-site request forgery
Master Slider – Responsive Touch Slider is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD4.3
|
| Dec 23, 2018 |
CVE-2018-20368
Master Slider: Cross-site scripting
Master Slider is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|