Vendorsi13websolutionthumbnail_slider_with_lightboxall versions
Vulnerabilities

i13websolution I Thirteen Web Solution Thumbnail Slider With Lightbox

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2023-5820
The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the addedit functionality. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Published 2023-10-27 · Modified
9.6EPSS 0.003
CVE-2015-10146
Thumbnail Slider With Lightbox <= 1.0.4 - Authenticated (Admin+) SQL Injection
Published 2025-10-29 · Analyzed
4.9EPSS 0.003
CVE-2023-5621
Thumbnail Slider With Lightbox <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via Image Title
Published 2023-10-18 · Modified
4.8EPSS 0.004
CVE-2023-5531
Thumbnail Slider With Lightbox <= 1.0 - Cross-Site Request Forgery
Published 2023-10-12 · Modified
4.3EPSS 0.003