Responsive Flickr Slideshow

Responsive Flickr Slideshow has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; all 2 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10. 2025 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).

Every one of the 2 issues recorded for Responsive Flickr Slideshow has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Responsive Flickr Slideshow is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Responsive Flickr Slideshow vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2024-13660

Responsive Flickr Slideshow <= 2.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

2 records
Responsive Flickr Slideshow banner
Latestv2.7.0

Responsive Flickr Slideshow

Robert

Author

Robert

4.8(6)
96/100
Last Updated
2025-02-21 (2y ago)
Active Installs
200+
Downloads
13,615
Requires WP
3.0.0+
Requires PHP
0+
Tested up to
WP 6.7.7
Created
2014-05-27 (13y ago)

Embeds a responsive slideshow of Flickr images from any album or photoset Shortcodes are of the format: [fshow url=https://flic.kr/s/aHsiP3Xyxx] or [fshow photosetid=72157627847553181] The default parameters for api key, username, user_id and photosetid can have values set using the plugin options page that will then be used by default whenever they are omitted from the shortcode.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C