Block Slider – Responsive Image Slider, Video Slider & Post Slider Security & Risk Analysis

wordpress.org/plugins/block-slider

Create Responsive Sliders using WordPress Blocks. Image slider, video slider, YouTube slider, post slider, product slider, WooCommerce slider & more.

4K active installs v2.2.3 PHP 5.6+ WP 5.7+ Updated Feb 21, 2024
image-sliderpost-sliderresponsive-slidersliderwordpress-slider
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEJan 7, 2026
Download
Safety Verdict

Is Block Slider – Responsive Image Slider, Video Slider & Post Slider Safe to Use in 2026?

Use With Caution

Score 63/100

Block Slider – Responsive Image Slider, Video Slider & Post Slider has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Jan 7, 2026Updated 2yr ago
Risk Assessment

The block-slider plugin v2.2.3 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries by exclusively using prepared statements, and the taint analysis shows no concerning flows. The plugin also appears to handle output escaping reasonably well, with a significant majority of outputs being properly escaped. However, there are significant concerns that overshadow these strengths. The plugin exposes a critical attack vector with a single unprotected REST API route, making it vulnerable to unauthorized access and manipulation. Furthermore, the absence of any nonce or capability checks across all entry points is a major security flaw, leaving the plugin susceptible to various attacks if a vulnerable endpoint is discovered. The vulnerability history, including a recently disclosed medium-severity CVE that remains unpatched, highlights a pattern of security weaknesses, specifically related to missing authorization, that have been present in the plugin's development. This historical context, combined with the current lack of authorization checks, suggests a recurring issue that requires immediate attention. While the plugin has some good coding habits, the identified vulnerabilities, particularly the unprotected REST API and the complete lack of authorization controls, place it at a considerable risk. The presence of an unpatched CVE further exacerbates this risk, making it imperative for users to update or mitigate the plugin's exposure.

Key Concerns

  • Unprotected REST API route
  • No nonce checks found
  • No capability checks found
  • Unpatched CVE (medium severity)
  • Bundled outdated library (Freemius v1.0)
  • Low output escaping rate
Vulnerabilities
1 published

Block Slider – Responsive Image Slider, Video Slider & Post Slider Security Vulnerabilities

CVEs by Year

1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-22522medium · 4.3Missing Authorization

Block Slider <= 2.2.3 - Missing Authorization

Jan 7, 2026Unpatched
Version History

Block Slider – Responsive Image Slider, Video Slider & Post Slider Release Timeline

v2.2.3Current1 CVE
v2.2.21 CVE
v2.2.11 CVE
v2.2.01 CVE
v2.1.81 CVE
v2.1.71 CVE
v2.1.61 CVE
v2.1.51 CVE
v2.1.41 CVE
v2.1.31 CVE
v2.1.21 CVE
v2.1.11 CVE
v2.1.01 CVE
v2.0.01 CVE
v1.2.91 CVE
v1.2.81 CVE
v1.2.71 CVE
v1.2.61 CVE
v1.2.51 CVE
v1.2.41 CVE
Code Analysis
Analyzed Mar 16, 2026

Block Slider – Responsive Image Slider, Video Slider & Post Slider Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
5
12 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

100% prepared2 total queries

Output Escaping

71% escaped17 total outputs
Attack Surface
1 unprotected

Block Slider – Responsive Image Slider, Video Slider & Post Slider Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

POST/wp-json/blockslider/v1/library-proxyapp\Library.php:32
WordPress Hooks 12
filterrender_block_cakewp/block-sliderapp\Animation.php:19
actionrest_api_initapp\Library.php:23
filtertemplate_redirectapp\Preview.php:30
actionwp_headapp\Preview.php:31
filterrender_block_cakewp/block-slideapp\QuerySlider.php:25
filterrender_block_cakewp/block-sliderapp\QuerySlider.php:26
filterrender_block_cakewp/no-resultapp\QuerySlider.php:27
filterrender_block_contextapp\QuerySlider.php:184
filterblockslider_postapp\Shortcode.php:136
filterdefault_titleapp\Slider.php:185
filterblockslider_postapp\Views\PageTemplates\Single.php:16
filterblockslider_query_argsapp\WooQuerySupport.php:25
Maintenance & Trust

Block Slider – Responsive Image Slider, Video Slider & Post Slider Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedFeb 21, 2024
PHP min version5.6
Downloads86K

Community Trust

Rating64/100
Number of ratings26
Active installs4K
Developer Profile

Block Slider – Responsive Image Slider, Video Slider & Post Slider Developer Profile

Munir Kamal

8 plugins · 48K total installs

67
trust score
Avg Security Score
83/100
Avg Patch Time
313 days
View full developer profile
Detection Fingerprints

How We Detect Block Slider – Responsive Image Slider, Video Slider & Post Slider

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/block-slider/dist/admin/admin.js/wp-content/plugins/block-slider/dist/admin/admin.css/wp-content/plugins/block-slider/dist/frontend/frontend.js/wp-content/plugins/block-slider/dist/blocks-library/block-slider/block-slider-frontend.css/wp-content/plugins/block-slider/dist/blocks-library/block-slider/block-slider.js/wp-content/plugins/block-slider/dist/blocks-library/block-slider/block-slider-editor.css/wp-content/plugins/block-slider/blocks/block-slider/
Script Paths
dist/admin/admin.jsdist/frontend/frontend.jsdist/blocks-library/block-slider/block-slider-frontend.cssdist/blocks-library/block-slider/block-slider.jsdist/blocks-library/block-slider/block-slider-editor.css

HTML / DOM Fingerprints

CSS Classes
wp-block-cakewp-block-slider
Data Attributes
data-block-slider-id
JS Globals
blockslider
FAQ

Frequently Asked Questions about Block Slider – Responsive Image Slider, Video Slider & Post Slider