The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'delay' Post Meta Setting in all versions up to, and including, 3.111.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages [truncated]
A critical vulnerability, CVE-2026-39465, was discovered in the Responsive Slider by MetaSlider plugin for WordPress, version 3.106.0 and earlier. This vulnerability allows for remote code execution (RCE) and has a CVSS score of 9.1, indicating a high severity level. The vulnerability was published on June 15, 2026, and last modified on the same day.