PLUGIN SECURITY
Is Slider Revolution safe?
Slider, gallery, carousel plugin for WordPress. Build your image slider, video slider, post slider, YouTube slider, or WooCommerce product slider.
What this plugin does
- Slug:
revslider - Author: MetaSlider
- 500000+ active installs
- 92/100 rating (737 reviews on wordpress.org)
- 34983629 all-time downloads
- On WordPress.org since 2013-02-15
carousel slidergalleryimage sliderslidervideo slider
Maintenance status
- Latest known version: 3.111.2
- Last updated: 2026-08-19 7:51pm GMT
- Tested up to WordPress: 7.1
- Requires PHP: 7.0+
Known vulnerabilities
22 known CVEs on file for Slider Revolution.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-57678 | Slider Revolution [revslider] < 7.1.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 7.1.0 | 7.1.0 | 2026-06-30 | ⚠ update needed |
| CVE-2026-7542 | Slider Revolution [revslider] < 7.0.11 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 6.5 | < 7.0.11 | 7.0.11 | 2026-06-08 | ⚠ update needed |
| CVE-2026-9050 | Slider Revolution [revslider] < 6.7.56 | Missing Authorization | Medium 4.3 | < 6.7.56 | 6.7.56 | 2026-06-01 | ⚠ update needed |
| CVE-2026-9048 | Slider Revolution [revslider] < 7.0.15 | Incorrect Authorization | Medium 4.3 | < 7.0.15 | 7.0.15 | 2026-06-01 | ⚠ update needed |
| CVE-2026-6728 | Slider Revolution [revslider] < 7.0.10 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 5.3 | < 7.0.10 | 7.0.10 | 2026-05-19 | ⚠ update needed |
| CVE-2026-6692 | Slider Revolution [revslider] < 7.0.11 | Unrestricted Upload of File with Dangerous Type | High 8.8 | < 7.0.11 | 7.0.11 | 2026-05-06 | ⚠ update needed |
| CVE-2025-10249 | Slider Revolution [revslider] < 6.7.38 | Relative Path Traversal | Medium 6.5 | < 6.7.38 | 6.7.38 | 2025-10-08 | ⚠ update needed |
| CVE-2024-8107 | Slider Revolution [revslider] < 6.7.19 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 6.7.19 | 6.7.19 | 2024-09-30 | ⚠ update needed |
+ 17 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-37449 | Slider Revolution [revslider] < 6.7.14 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.9 | < 6.7.14 | 6.7.14 | 2024-06-28 | ⚠ update needed |
| CVE-2024-4581 | Slider Revolution [revslider] < 6.7.11 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 6.7.11 | 6.7.11 | 2024-06-03 | ⚠ update needed |
| CVE-2024-4637 | Slider Revolution [revslider] < 6.7.11 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 6.7.11 | 6.7.11 | 2024-06-03 | ⚠ update needed |
| CVE-2024-34444 | Slider Revolution [revslider] < 6.7.0 | Missing Authorization | High 7.1 | < 6.7.0 | 6.7.0 | 2024-05-28 | ⚠ update needed |
| CVE-2024-34443 | Slider Revolution [revslider] < 6.7.11 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.9 | < 6.7.11 | 6.7.11 | 2024-05-28 | ⚠ update needed |
| CVE-2024-4092 | Slider Revolution [revslider] < 6.7.8 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 6.7.8 | 6.7.8 | 2024-04-30 | ⚠ update needed |
| CVE-2024-2306 | Slider Revolution [revslider] < 6.7.0 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | Medium 6.4 | < 6.7.0 | 6.7.0 | 2024-04-08 | ⚠ update needed |
| CVE-2023-6528 | Slider Revolution [revslider] < 6.6.19 | Improper Control of Generation of Code ('Code Injection') | High 8.8 | < 6.6.19 | 6.6.19 | 2023-11-30 | ⚠ update needed |
| — | Slider Revolution [revslider] < 3.0.96 | — | Unknown | < 3.0.96 | 3.0.96 | 2023-11-26 | ✓ fixed in latest |
| CVE-2023-47784 | Slider Revolution [revslider] < 6.6.16 | Unrestricted Upload of File with Dangerous Type | High 8.4 | < 6.6.16 | 6.6.16 | 2023-11-14 | ⚠ update needed |
| CVE-2023-47772 | Slider Revolution [revslider] < 6.6.15 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 6.6.15 | 6.6.15 | 2023-11-14 | ⚠ update needed |
| CVE-2023-2359 | Slider Revolution [revslider] < 6.6.13 | Improper Control of Generation of Code ('Code Injection') | High 8.8 | < 6.6.13 | 6.6.13 | 2023-05-22 | ⚠ update needed |
| CVE-2015-1579 | Slider Revolution [revslider] < 4.1.5 (unfixed) | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Unknown | < 4.1.5 | 4.1.5 | 2015-02-11 | ⚠ update needed |
| CVE-2015-5151 | Slider Revolution [revslider] < 4.2.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Unknown | < 4.2.3 | 4.2.3 | 2014-12-17 | ⚠ update needed |
| — | Slider Revolution [revslider] < 3.0.96 | — | Unknown | < 3.0.96 | 3.0.96 | 2014-11-26 | ✓ fixed in latest |
| CVE-2014-9735 | Slider Revolution [revslider] < 3.0.96 | — | Unknown | < 3.0.96 | 3.0.96 | 2014-11-25 | ✓ fixed in latest |
| — | Slider Revolution [revslider] < 6.7.37 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Medium 6.5 | < 6.7.37 | 6.7.37 | 0000-00-00 | ⚠ update needed |
How to fix it
Keep Slider Revolution updated — 3.111.2 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Smart Slider 3 — 800000+ active installs — 98/100 (1123) — max PHP <8.0
- Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery — 300000+ active installs — 86/100 (4339) — max PHP 8.4
- Firelight Lightbox — 200000+ active installs — 96/100 (355) — max PHP 8.4
- Photo Gallery by 10Web – Mobile-Friendly Image Gallery — 100000+ active installs — 90/100 (1581)
- Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel — 100000+ active installs — 96/100 (986)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.