Card flip image slideshow
Card flip image slideshow has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Card flip image slideshow has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Peter Thaleikis. Card flip image slideshow is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.1.12.
CVE-2025-30983Card flip image slideshow <= 1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Card flip image slideshow
Author
gopiplus
This Card flip image slideshow script utilizes CSS3 transform to rotate images with unhinge animation. It supports both auto and manual method for images display. This unhinge effect works in all browsers that support CSS3 transform. In non-supporting browsers version, a standard slide down effect is used instead. Check official website for live demo http://www.gopiplus.com/work/2019/12/15/card-flip-image-slideshow-wordpress-plugin/ Live Demo : Live Demo More Information : More Information Plugin : Plugin URI Supports two different display modes Auto and Manual. In auto mode, slideshow pauses when the mouse rolls over the slideshow. Supports persistence of last viewed slide within a browser session, so reloading the page recalls that slide. Customize the unhinge animation to either drop from the left or right side or any origin. Plug-in features Supports all major browsers. Responsive width. Slideshow auto play option. Widget option for sidebar. Short code option for posts and pages.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C