GPP Slideshow
GPP Slideshow has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for GPP Slideshow has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by HLog. GPP Slideshow is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 3.7.41.
CVE-2025-28996GPP Slideshow <= 1.3.5 - Missing Authorization
Read the full analysisVulnerability Records
GPP Slideshow
Author
Thad Allender
The GPP Slideshow plugin for WordPress allows you to create minimalist image slideshows using the new Gallery post type or using WordPress’ built in [gallery] shortcode on Posts and Pages. The plugin comes with a Widget for easily inserting a specific gallery into any widgetized are on your theme. This plugin requires WordPress 3.1 and works best with a Graph Paper Press theme. Live demo Release info Support
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C