← WordPress Vulnerabilities
WordPress security by component

Slider by 10Web

Slider by 10Web is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published Mar 25, 2025; the highest CVE/CNA score is 8.8.

Plugin slug: slider

CVE-2024-10566: Slider by 10Web: Cross-site scripting

Slider by 10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedMar 25, 2025
Safe version guidanceSee mitigation notes
Safe version
Mar 25, 2025 CVE-2024-10566
Slider by 10Web: Cross-site scripting
Slider by 10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Mar 25, 2025 CVE-2024-10565
Slider by 10Web: Cross-site scripting
Slider by 10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Sep 30, 2024 CVE-2024-8283
Slider by 10Web: Cross-site scripting
Slider by 10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Jul 31, 2024 CVE-2024-6408
Slider by 10Web: Cross-site scripting
Slider by 10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Jul 11, 2024 CVE-2024-6026
Slider by 10Web: Cross-site scripting
Slider by 10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD5.4
Dec 26, 2022 CVE-2022-4197
Sliderby10Web: Cross-site scripting
Sliderby10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Mar 18, 2021 CVE-2021-24132
Slider by 10Web: SQL injection
Slider by 10Web is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD8.8