Slick Slider
Slick Slider has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Slick Slider has a vendor fix available, so running the current release closes it.
All of these findings were reported by testoun. Slick Slider is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.8.30.
CVE-2026-16537Slick Slider <= 0.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records
Slick Slider
Author
Philipp Bammes
Slick Slider turns your native WordPress galleries into beautiful fully responsive sliders. Choose from a wide range of options to adjust all sliders to your needs with a simple click. Slick Slider allows you to change default options valid for all sliders or to adjust them on a per gallery base. Available options (amongst others): Turn autoplay on or off Change default speed of animation and autoplay Turn fade effect on or off Turn arrows and dots on or off Use center mode to see partial prev/next slides Make slider infinite Pause slider on hover Adjust slides to scroll and slides to show Enable lazy loading for better performance Stack images up in rows Turn vertical sliders and RTL support on or off Link your images using native gallery settings Many more Note: No support for slick’s responsive options feature (different options at different breakpoints) at the moment. Note: Slick Slider requires at least PHP 5.6! That means it won’t work on websites which are powered by PHP older than version 5.6! If you don’t know your website’s PHP version ask your host and request an update if necessary. Click here for more information. Slick Slider uses the awesome slick slider written by Ken Wheeler.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C