cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwp-responsive-thumbnail-slider wp-responsive-thumbnail-slider

Direction: descending
Aug 03, 2026

Thumbnail carousel slider # CVE-2026-18344

CVE, Research URL

CVE-2026-18344

Date
Aug 01, 2026
Research Description
The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in versions up to, and excluding, 1.1.53. This is due to insufficient input sanitization and output escaping in the responsive_thumbnail_image_management() function, which echoes $_GET['id'] directly into a double-quoted HTML attribute with no esc_attr() call. The only guard is a loose PHP numeric comparison ($_GET['id']>0) that a string beginning with a numeric prefix trivially satisfies, and the addslashes() applied by wp_magic_quotes() is inert in HTML-attribute context because backslash is not an HTML escape character. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.
Affected versions
max 1.1.53.
Status
vulnerable
Jun 16, 2026

Thumbnail carousel slider # 37194376f91f764b968df935c7b72525e921727e

Date
Aug 28, 2015
Research Description
Thumbnail carousel slider [wp-responsive-thumbnail-slider] < 1.1 WordPress Responsive Thumbnail Slider Plugin 1.0 - Arbitrary File Upload Responsive Thumbnail Slider plugin is prone to an arbitrary file upload vulnerability, that allows an attacker to upload shell as a image. Update the plugin.
Affected versions
max 1.1.
Status
vulnerable

Thumbnail carousel slider # 5313941a62a76e09a8129aeac240b3dcb0f71279

Date
Aug 28, 2015
Research Description
Thumbnail carousel slider [wp-responsive-thumbnail-slider] < 1.1 WordPress Responsive Thumbnail Slider Plugin <= 1.0 - Multiple Vulnerabilities This plugin is prone to a cross site scripting and cross site request forgery vulnerabilities. Update the plugin.
Affected versions
max 1.1.
Status
vulnerable

Thumbnail carousel slider # 3706ded923680765400114b00fd54bb18e696e43

Date
Dec 28, 2020
Research Description
Thumbnail carousel slider [wp-responsive-thumbnail-slider] < 1.0.1 Thumbnail carousel slider < 1.0.1 - Stored Cross-Site Scripting and Cross-Site Request Forgery The Thumbnail carousel slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting and Cross-Site Request Forgery via the ‘title’ parameter in versions before 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The Stored Cross-Site scripting vulnerability requires authentication with admin-level privileges while the Cross-Site Request Forgery does not require any authentication.
Affected versions
max 1.0.1.
Status
vulnerable

Thumbnail carousel slider # 87b6ffa1b216a58f32c7f4ed33b3b05634d2bf03

Date
Dec 28, 2020
Research Description
Thumbnail carousel slider [wp-responsive-thumbnail-slider] < 1.0.1 WordPress Thumbnail carousel slider plugin <= 1.0 - Stored Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerabilities Stored Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerabilities found by Arash Khazaei in WordPress Thumbnail carousel slider plugin (versions <= 1.0).
Affected versions
max 1.0.1.
Status
vulnerable

Thumbnail carousel slider # b2d79421e3ff5522255645c82cf46a4f80ac814c

Date
Aug 29, 2015
Research Description
Thumbnail carousel slider [wp-responsive-thumbnail-slider] < 1.0.1 Responsive Thumbnail Slider < 1.0.1 - Authenticated (Subscriber+) Arbitrary File Upload The Responsive Thumbnail Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type sanitization in the via the image uploader in versions up to 1.0.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affected sites server using a double extension which may make remote code execution possible.
Affected versions
max 1.0.1.
Status
vulnerable

Thumbnail carousel slider # 2c785942-0641-4e55-96bd-5ab405353002

Date
-
Research Description
Responsive Thumbnail Slider [wp-responsive-thumbnail-slider] < 1.0.1 Thumbnail Carousel Slider &lt; 1.0.1 - Authenticated Shell Upload &amp; CSRF The original advisory states that this vulnerability is exploitable with editor and author roles but this is incorrect. Only the administrator role by default can trigger this vulnerability. However, CSRF on the image upload form makes this exploitable by a malicious actor.
Affected versions
max 1.0.1.
Status
vulnerable

Thumbnail carousel slider # ab7ac7d5-a68d-4af7-a38a-65aa940337f1

Date
-
Research Description
Responsive Thumbnail Slider [wp-responsive-thumbnail-slider] < 1.0.1 Thumbnail Carousel Slider &lt; 1.0.1 - Stored Cross-Site Scripting (XSS) &amp; CSRF The original advisory states that this vulnerability is exploitable with editor and author roles but this is incorrect. Only the administrator role by default can trigger this vulnerability. However, CSRF on the image upload form makes this exploitable by a malicious actor.
Affected versions
max 1.0.1.
Status
vulnerable
Jul 29, 2025

Thumbnail carousel slider # CVE-2015-10144

CVE, Research URL

CVE-2015-10144

Date
Jul 25, 2025
Research Description
The Responsive Thumbnail Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type sanitization in the via the image uploader in versions up to 1.0.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affected sites server using a double extension which may make remote code execution possible.
Affected versions
max 1.0.1.
Status
vulnerable
Mar 16, 2025

Thumbnail carousel slider # CVE-2019-25222

CVE, Research URL

CVE-2019-25222

Date
Mar 15, 2025
Research Description
The Thumbnail carousel slider plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected versions
max 1.0.5.
Status
vulnerable
Jun 07, 2024

Thumbnail carousel slider # 2d6e889a1030d4f63f5210d1ffb851b3f4bc56b8

Date
Dec 28, 2020
Research Description
Thumbnail carousel slider [wp-responsive-thumbnail-slider] < 1.0.1 WordPress Thumbnail carousel slider plugin <= 1.0 - Authenticated Shell Upload and Cross-Site Request Forgery (CSRF) vulnerabilities Authenticated Shell Upload and Cross-Site Request Forgery (CSRF) vulnerabilities found by Arash Khazaei in WordPress Thumbnail carousel slider plugin (versions <= 1.0).
Affected versions
max 1.0.1.
Status
vulnerable

Thumbnail carousel slider # CVE-2023-1915

CVE, Research URL

CVE-2023-1915

Date
May 15, 2023
Research Description
The Thumbnail carousel slider WordPress plugin before 1.1.10 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting vulnerability which could be used against high privilege users such as admin.
Affected versions
max 1.1.10.
Status
vulnerable

Thumbnail carousel slider # CVE-2023-2120

CVE, Research URL

CVE-2023-2120

Date
Apr 18, 2023
Research Description
The Thumbnail carousel slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 1.1.10.
Status
vulnerable

Thumbnail carousel slider # CVE-2023-5821

CVE, Research URL

CVE-2023-5821

Date
Oct 27, 2023
Research Description
The Thumbnail carousel slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing nonce validation on the deleteselected function. This makes it possible for unauthenticated attackers to delete sliders in bulk via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 1.0.1.
Status
vulnerable