PLUGIN SECURITY

Is Slider Revolution safe?

Slider, gallery, carousel plugin for WordPress. Build your image slider, video slider, post slider, YouTube slider, or WooCommerce product slider.

What this plugin does

  • Slug: revslider
  • Author: MetaSlider
  • 500000+ active installs
  • 92/100 rating (737 reviews on wordpress.org)
  • 34983629 all-time downloads
  • On WordPress.org since 2013-02-15

carousel slidergalleryimage sliderslidervideo slider

Maintenance status

  • Latest known version: 3.111.2
  • Last updated: 2026-08-19 7:51pm GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 7.0+

Known vulnerabilities

22 known CVEs on file for Slider Revolution.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-57678 Slider Revolution [revslider] < 7.1.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 7.1.0 7.1.0 2026-06-30 ⚠ update needed
CVE-2026-7542 Slider Revolution [revslider] < 7.0.11 Exposure of Sensitive Information to an Unauthorized Actor Medium 6.5 < 7.0.11 7.0.11 2026-06-08 ⚠ update needed
CVE-2026-9050 Slider Revolution [revslider] < 6.7.56 Missing Authorization Medium 4.3 < 6.7.56 6.7.56 2026-06-01 ⚠ update needed
CVE-2026-9048 Slider Revolution [revslider] < 7.0.15 Incorrect Authorization Medium 4.3 < 7.0.15 7.0.15 2026-06-01 ⚠ update needed
CVE-2026-6728 Slider Revolution [revslider] < 7.0.10 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 7.0.10 7.0.10 2026-05-19 ⚠ update needed
CVE-2026-6692 Slider Revolution [revslider] < 7.0.11 Unrestricted Upload of File with Dangerous Type High 8.8 < 7.0.11 7.0.11 2026-05-06 ⚠ update needed
CVE-2025-10249 Slider Revolution [revslider] < 6.7.38 Relative Path Traversal Medium 6.5 < 6.7.38 6.7.38 2025-10-08 ⚠ update needed
CVE-2024-8107 Slider Revolution [revslider] < 6.7.19 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 6.7.19 6.7.19 2024-09-30 ⚠ update needed
+ 17 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-37449 Slider Revolution [revslider] < 6.7.14 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.9 < 6.7.14 6.7.14 2024-06-28 ⚠ update needed
CVE-2024-4581 Slider Revolution [revslider] < 6.7.11 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 6.7.11 6.7.11 2024-06-03 ⚠ update needed
CVE-2024-4637 Slider Revolution [revslider] < 6.7.11 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 6.7.11 6.7.11 2024-06-03 ⚠ update needed
CVE-2024-34444 Slider Revolution [revslider] < 6.7.0 Missing Authorization High 7.1 < 6.7.0 6.7.0 2024-05-28 ⚠ update needed
CVE-2024-34443 Slider Revolution [revslider] < 6.7.11 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.9 < 6.7.11 6.7.11 2024-05-28 ⚠ update needed
CVE-2024-4092 Slider Revolution [revslider] < 6.7.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 6.7.8 6.7.8 2024-04-30 ⚠ update needed
CVE-2024-2306 Slider Revolution [revslider] < 6.7.0 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) Medium 6.4 < 6.7.0 6.7.0 2024-04-08 ⚠ update needed
CVE-2023-6528 Slider Revolution [revslider] < 6.6.19 Improper Control of Generation of Code ('Code Injection') High 8.8 < 6.6.19 6.6.19 2023-11-30 ⚠ update needed
Slider Revolution [revslider] < 3.0.96 Unknown < 3.0.96 3.0.96 2023-11-26 ✓ fixed in latest
CVE-2023-47784 Slider Revolution [revslider] < 6.6.16 Unrestricted Upload of File with Dangerous Type High 8.4 < 6.6.16 6.6.16 2023-11-14 ⚠ update needed
CVE-2023-47772 Slider Revolution [revslider] < 6.6.15 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 6.6.15 6.6.15 2023-11-14 ⚠ update needed
CVE-2023-2359 Slider Revolution [revslider] < 6.6.13 Improper Control of Generation of Code ('Code Injection') High 8.8 < 6.6.13 6.6.13 2023-05-22 ⚠ update needed
CVE-2015-1579 Slider Revolution [revslider] < 4.1.5 (unfixed) Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Unknown < 4.1.5 4.1.5 2015-02-11 ⚠ update needed
CVE-2015-5151 Slider Revolution [revslider] < 4.2.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 4.2.3 4.2.3 2014-12-17 ⚠ update needed
Slider Revolution [revslider] < 3.0.96 Unknown < 3.0.96 3.0.96 2014-11-26 ✓ fixed in latest
CVE-2014-9735 Slider Revolution [revslider] < 3.0.96 Unknown < 3.0.96 3.0.96 2014-11-25 ✓ fixed in latest
Slider Revolution [revslider] < 6.7.37 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 6.5 < 6.7.37 6.7.37 0000-00-00 ⚠ update needed

How to fix it

Keep Slider Revolution updated — 3.111.2 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.