CVE · Critical

CVE-2026-39465 — Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider] < 3.107.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-39465 Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider] < 3.107.0 Improper Control of Generation of Code ('Code Injection') Critical 9.1 < 3.107.0 3.107.0 2026-04-20

CVE-2026-39465

The MetaSlider plugin for WordPress contains a critical vulnerability that allows malicious users with elevated permissions to inject and run arbitrary code on the server, compromising system security in versions prior to 3.106.1. This flaw is present across all affected iterations of the software, from its initial release up to and including version 3.106.0.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.