← WordPress Vulnerabilities
WordPress security by component

Master Slider

Master Slider is a WordPress component with 20 published CVE records in this archive. The latest tracked vulnerability was published Jun 25, 2026; the highest CVE/CNA score is 8.3.

Plugin slug: master-slider

CVE-2026-56014: Master Slider: Cross-site scripting

Master Slider is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.11.2.

PublishedJun 25, 2026
Known safe version> 3.11.2
Safe version
Jun 25, 2026 CVE-2026-56014
Master Slider: Cross-site scripting
Master Slider is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.11.2.
> 3.11.2
CVE7.1
NVDPending
May 27, 2026 CVE-2026-48968
Master Slider: Cross-site scripting
Master Slider is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.10.8.
3.10.9
CVE6.5
NVDPending
Sep 22, 2025 CVE-2025-58025
Master Slider: Cross-site scripting
Master Slider is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Jun 17, 2025 CVE-2025-5291
Master Slider – Responsive Touch Slider: Cross-site scripting
Master Slider – Responsive Touch Slider is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 19, 2025 CVE-2025-39412
Master Slider: A security weakness
Master Slider is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Mar 05, 2025 CVE-2024-13757
Master Slider – Responsive Touch Slider: Cross-site scripting
Master Slider – Responsive Touch Slider is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 05, 2025 CVE-2024-11731
Master Slider – Responsive Touch Slider: Cross-site scripting
Master Slider – Responsive Touch Slider is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Feb 19, 2025 CVE-2024-12173
Master Slider: Cross-site scripting
Master Slider is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE3.5
NVDPending
Jul 26, 2024 CVE-2024-6490
Master Slider: Cross-site request forgery
Master Slider is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.5
NVDPending
Jun 20, 2024 CVE-2024-37222
Master Slider: Cross-site scripting
Master Slider is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Jun 19, 2024 CVE-2023-50900
Master Slider: Cross-site request forgery
Master Slider is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Jun 18, 2024 CVE-2024-4375
Master Slider – Responsive Touch Slider: Cross-site scripting
Master Slider – Responsive Touch Slider is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 01, 2024 CVE-2023-6382
Master Slider – Responsive Touch Slider: Cross-site scripting
Master Slider – Responsive Touch Slider is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 21, 2024 CVE-2024-4470
Master Slider – Responsive Touch Slider: Cross-site scripting
Master Slider – Responsive Touch Slider is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 18, 2024 CVE-2024-32600
Master Slider: Code execution
Master Slider is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.3
NVD9.6
Apr 18, 2024 CVE-2024-32580
Master Slider: Cross-site scripting
Master Slider is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Mar 02, 2024 CVE-2024-1449
Master Slider – Responsive Touch Slider: Cross-site scripting
Master Slider – Responsive Touch Slider is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 02, 2024 CVE-2024-0611
Master Slider – Responsive Touch Slider: Cross-site scripting
Master Slider – Responsive Touch Slider is affected by cross-site scripting. Exploitation requires at least editor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD4.8
Mar 02, 2024 CVE-2023-6326
Master Slider – Responsive Touch Slider: Cross-site request forgery
Master Slider – Responsive Touch Slider is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD4.3
Dec 23, 2018 CVE-2018-20368
Master Slider: Cross-site scripting
Master Slider is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4