Content Slideshow

Content Slideshow has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Content Slideshow has a vendor fix available, so running the current release closes it.

All of these findings were reported by Gilang - DJ. Content Slideshow is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Content Slideshow vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2026-8873

Content Slideshow <= 2.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

Read the full analysis

Vulnerability Records

1 records
Plugin Profile
Latestv2.5

Content Slideshow

Nick Halsey

Author

Nick Halsey

0.0(0)
0/100
Last Updated
2026-07-14 (1mo ago)
Active Installs
10+
Downloads
6,099
Requires WP
4.1+
Requires PHP
0+
Tested up to
WP 7.0.4
Created
2014-01-08 (13y ago)

This plugin creates a fullscreen slideshow that displays randomly-selected pictures from your media library. Designed to display pictures related to your business/organization in the background at an event or in your office, there is no need to configure any settings or controls. Image captions/descriptions are automatically displayed as well, and can be configured based on your needs. Once activated, you can view the slideshow by visiting http://yourdomain.com/slideshow. All JPEG images will be displayed (since .jpg is best for pictures, while .png and .gif are typically used for graphics). Please note that it is not currently possible to pause the slideshow or go back; the slideshow is not designed for personal viewing. However, clicking/tapping on the image will open its attachment page in a new tab, allowing images to be contextualized or edited easily. The slideshow can also be embedded into your site via a widget or a shortcode. You can control some options by adjusting the url of the slideshow. Parameters are controlled via query string (and widget options and shortcode attributes). size is the size of the image to load, either thumbnail (discouraged), medium, large, full, or auto, which uses medium or large depending on wp_is_mobile(). year is the 4-digit numeric year in which the images were published. month is the numeric month in which the images were published (between 1 and 12), typically but not necessarily used in conjunction with year. mode defines a subset of images to use, such as featured for featured images only. captions controls the captions display: either auto, none, title, titlecaption, caption, or description. Caption data is read from the image attachment post and can be updated in the media library. Using all options, for example: http://example.com/slideshow?size=full&year=2014&month=4&mode=featured&captions=titlecaption You can see it in action here.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C