← WordPress Vulnerabilities
WordPress security by component

Thumbnail carousel slider

Thumbnail carousel slider is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Mar 15, 2025; the highest CVE/CNA score is 6.1.

Plugin slug: wp-responsive-thumbnail-slider

CVE-2019-25222: Thumbnail carousel slider: SQL injection

Thumbnail carousel slider is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.

PublishedMar 15, 2025
Safe version guidanceSee mitigation notes
Safe version
Mar 15, 2025 CVE-2019-25222
Thumbnail carousel slider: SQL injection
Thumbnail carousel slider is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE4.9
NVD4.9
Oct 27, 2023 CVE-2023-5821
Thumbnail carousel slider: Cross-site request forgery
Thumbnail carousel slider is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD6.5
Apr 18, 2023 CVE-2023-2120
Thumbnail carousel slider: Cross-site scripting
Thumbnail carousel slider is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Apr 18, 2023 CVE-2023-2119
Responsive Filterable Portfolio: Cross-site scripting
Responsive Filterable Portfolio is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1