Metaslider develops WordPress slider, gallery, and carousel plugins that are broadly embedded across websites despite a narrow product portfolio. The vendor's vulnerability profile centers durably on cross-site scripting weaknesses arising from improper input neutralization in dynamically generated web content, a recurrent risk in template-driven WordPress components. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Metaslider over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-1473MEDIUM The Slider, Gallery, and Carousel by MetaSlider WordPress plugin 3.29.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross | Apr 17, 2023 | 6.1 | 21 | NO | NO |
CVE-2022-2823MEDIUM The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.27.9 does not sanitise and escape some of its Gallery Image parameters, which could allow high privilege u | Oct 10, 2022 | 4.8 | 19 | NO | NO |
CVE-2025-5337MEDIUM The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘aria-label’ parameter in all versions up to, and includin | Jun 14, 2025 | 5.4 | 16 | NO | NO |
CVE-2024-3285MEDIUM The Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Slideshows plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'metaslider' sh | Apr 11, 2024 | 5.4 | 16 | NO | NO |
The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise and escape some of its settings, which could allow high privilege users such as ed | Mar 24, 2025 | 3.5 | 15 | NO | NO |
The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise and escape some of its settings, which could allow high privilege users such as ad | Mar 24, 2025 | 3.5 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Metaslider.
Media articles that mention a CVE ID that affects a product developed by Metaslider — matched by CVE ID, not by vendor name.