Simple SEO Slideshow
Simple SEO Slideshow has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Simple SEO Slideshow has a vendor fix available, so running the current release closes it.
All of these findings were reported by Gilang - DJ. Simple SEO Slideshow is installed on roughly 20 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2026-8900Simple SEO Slideshow <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
Read the full analysisVulnerability Records

Simple SEO Slideshow
Author
Nitroweb
Simple SEO Slideshow is a WordPress plugin/widget, for displaying on your site the images of a gallery from specified post or page. Widget options Title Page/Post ID Delay until next slide Height of your slideshow Show or not navigation bullets Show or not navigation arrows Show or not the caption Bullets Position Caption Position Exclude Images Randomize images order Choose what to link, image, caption, none, both New Features Now there is an option to link the image, the caption, none of them or both of them. You can randomize the order of the images. You can exclude image from the slideshow. You can use a shortcode to insert a slideshow of the gallery images of the post/page. You can also specify all the parameters of the widget. ex. [simpleslideshow sctitle=”test” scdelay=5 scheight=276 scdisplaybul=yes scdisplayarr=yes scrandomize=no sclinkwhat=image scdisplaycap=yes scbulpos=bottom-right sccappos=bottom-left] We have made a plugin for the editor to make your life easier. Just click the SEO Slideshow button.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C