CVE Database /
CVE-2026-39465
CVE · Critical
CVE-2026-39465 — Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider] < 3.107.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-39465
|
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider] < 3.107.0 |
Improper Control of Generation of Code ('Code Injection') |
Critical
9.1
|
< 3.107.0
|
3.107.0 |
2026-04-20 |
—
|
CVE-2026-39465
The MetaSlider plugin for WordPress contains a critical vulnerability that allows malicious users with elevated permissions to inject and run arbitrary code on the server, compromising system security in versions prior to 3.106.1. This flaw is present across all affected iterations of the software, from its initial release up to and including version 3.106.0.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings