Slideshow SE
Slideshow SE has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2024; all 4 are fixed as of September 2026. Their average CVSS score is 7.0, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2024 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 3 of the records (75%). Other recurring categories include PHP Remote File Inclusion.
Every one of the 4 issues recorded for Slideshow SE has a vendor fix available, so running the current release closes all known holes.
3 independent researchers contributed these findings, most of them (2) reported by Ngo Van Thien. Slideshow SE is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2024-35778Slideshow SE <= 2.5.17 - Authenticated (Author+) Limited Local File Inclusion
Read the full analysisVulnerability Records

Slideshow SE
Author
John West
Slideshow SE provides an easy way to add a slideshow to any WordPress installation. Any image can be loaded into the slideshow by picking it from the WordPress media page, even images you’ve already uploaded can be inserted into your slideshow right away! Fancy doing something crazy? You can create and use as many slideshows as you’d like, with different images, settings, and styles for each one of them. Features Gutenberg block Create as many slideshows with as many slides as you like Image slides Text slides YouTube Video slides Responsive Place it anywhere on your website Run multiple slideshows on the same page Change animations and handling Customizable stylesheets COMPLETELY FREE AND OPEN SOURCE Need the (uncompressed) source code? The forked code is available on GitHub. The original project’s source code is also in a GitHub repository. Links Original Project GitHub Forked Project GitHub
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C