VYPR

Image Slider by Ays- Responsive Slider and Carousel

by Ays Pro

CVEs (2)

  • CVE-2021-24463HigAug 2, 2021
    risk 0.57cvss 8.8epss 0.01

    The get_sliders() function in the Image Slider by Ays- Responsive Slider and Carousel WordPress plugin before 2.5.0 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in…

  • CVE-2025-14454MedDec 13, 2025
    risk 0.21cvss 4.3epss 0.00

    The Image Slider by Ays- Responsive Slider and Carousel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.0. This is due to missing or incorrect nonce validation on the bulk delete functionality. This makes it possible for…