VYPR

Thumbnail Slider With Lightbox

by WordPress

CVEs (4)

  • CVE-2023-5820CriOct 27, 2023
    risk 0.62cvss 9.6epss 0.00

    The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the addedit functionality. This makes it possible for unauthenticated attackers to upload arbitrary files…

  • CVE-2023-5621MedOct 18, 2023
    risk 0.29cvss 4.4epss 0.00

    The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Title field in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…

  • CVE-2023-5531MedOct 12, 2023
    risk 0.28cvss 4.3epss 0.00

    The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the delete functionality. This makes it possible for unauthenticated attackers to…

  • CVE-2015-10146Oct 29, 2025
    risk 0.00cvss epss 0.00

    The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. …