GutSlider – All in One Slider and Carousel Blocks for Gutenberg
GutSlider – All in One Slider and Carousel Blocks for Gutenberg has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for GutSlider – All in One Slider and Carousel Blocks for Gutenberg has a vendor fix available, so running the current release closes it.
All of these findings were reported by João G. Barbosa (4rCanJ0x!). GutSlider – All in One Slider and Carousel Blocks for Gutenberg is installed on roughly 6,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2024-37955GutSlider – All in One Block Slider <= 2.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

GutSlider – All in One Slider and Carousel Blocks for Gutenberg
Author
Binsaifullah
GutSlider is an all-in-one slider and carousel plugin for the WordPress block editor (Gutenberg). It adds a set of native slider blocks so you can build an image slider, content slider, post carousel, video carousel, testimonial slider, logo carousel or a before-after comparison slider directly on the page – no shortcodes, no page builder, no code. Every block is built with native Gutenberg components, so the editing experience feels like WordPress itself. Drag and drop your content, adjust the settings in the sidebar, and see the result live in the editor. Fast by design. GutSlider only loads its scripts and styles on pages where a slider block is actually used, generates a single minified CSS file per page instead of inline <style> tags, and ships without jQuery. Sliding is powered by Swiper JS for smooth, hardware-accelerated transitions. Why Choose GutSlider Slide any content – images, video, text, buttons, headings, or any other block. Conditional asset loading – scripts and styles load only on pages that use a slider block. No jQuery – modern, dependency-free JavaScript built on Swiper JS. Native block editor UI – built with Gutenberg components, not a bolted-on iframe or modal. Fully responsive – separate Desktop, Tablet and Mobile values for spacing, columns, typography and more. Complete slider controls – autoplay, loop, speed, effects, centered mode, free mode and column counts. Custom navigation and pagination – styles, positions, sizes, colours, gaps and remote navigation. CSS entrance animations – per-element animations with adjustable delay. Lightbox support – open carousel photos in a full-screen lightbox. Google Fonts and typography controls – full typography panel on every text element. Block patterns library – ready-made slider layouts you can insert and edit. Enable or disable blocks – turn off the blocks you do not use from the GutSlider dashboard. Translation ready – fully internationalised and RTL friendly. Free Slider and Carousel Blocks Static Slider – a classic hero slider with image, heading, text and buttons. Flexible Slider – slide any block content you like. Testimonial Slider – reviews with photo, rating, name and designation. Photo Carousel – image carousel with lightbox support. Logo Carousel – client and brand logo carousel. Before After Slider – drag-to-compare image comparison slider. Video Carousel – YouTube and Vimeo video carousel with custom thumbnails. Blog Post Slider – dynamic post slider and carousel with query controls. Marquee – continuous scrolling marquee for any content. Pro Slider and Carousel Blocks Need more? GutSlider Pro adds premium blocks and features: Shader Slider Shutters Slider Slicer Slider Fashion Slider Triple Slider Card Slider Hover Slider Tinder Slider Spring Carousel Panorama Carousel 3D Carousel Material Carousel Marquee Carousel WooCommerce Product Carousel WooCommerce Product Categories Carousel Thumbnail Gallery Navigation – thumbnail-based navigation for the Static and Blog Post sliders. Links All Demos Documentation Get GutSlider Pro External Services Google Fonts – When you select a Google Font in a block’s typography settings, the font stylesheet is requested from https://fonts.googleapis.com and the font files from https://fonts.gstatic.com on the pages where that block appears. Visitors’ IP address and browser user agent are sent to Google as part of that request. No request is made if you only use system or theme fonts. Google Terms of Service: https://policies.google.com/terms – Google Privacy Policy: https://policies.google.com/privacy Third Party Libraries Swiper JS (MIT) – slider and carousel engine. fslightbox – image lightbox for the Photo Carousel block.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C