
Master Slider – Responsive Touch Slider Security & Risk Analysis
wordpress.org/plugins/master-sliderBuild SEO friendly sliders fast and easy with touch swipe navigation that works smoothly across all devices.
Is Master Slider – Responsive Touch Slider Safe to Use in 2026?
Use With Caution
Score 62/100Master Slider – Responsive Touch Slider has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The Master Slider plugin exhibits a mixed security posture. While the static analysis shows a good number of entry points are protected by authentication and permission checks, a significant concern arises from the taint analysis revealing flows with unsanitized paths. This, coupled with a history of 18 known CVEs, including a critical one and a high severity one, suggests a pattern of past vulnerabilities that require careful attention. The presence of unpatched vulnerabilities, including a critical one, is a significant risk. The plugin also shows a concerning history of common vulnerability types such as Missing Authorization, Cross-site Scripting, SQL Injection, and Deserialization of Untrusted Data, indicating recurring weaknesses in input handling and authorization logic. While the plugin demonstrates some good practices like the use of prepared statements in a majority of SQL queries and proper output escaping in a good percentage of cases, the unpatched critical vulnerability and the presence of unsanitized paths in taint flows are serious red flags that necessitate immediate remediation.
Key Concerns
- Unpatched critical vulnerability
- Unpatched high severity vulnerability
- Unpatched medium severity vulnerability
- Taint flows with unsanitized paths
- Significant history of medium severity CVEs
- Common vulnerability types in history (XSS, SQLi, etc.)
- SQL queries not using prepared statements
- Output escaping not properly handled
Master Slider – Responsive Touch Slider Security Vulnerabilities
CVEs by Year
Severity Breakdown
18 total CVEs
Master Slider <= 3.11.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Master Slider <= 3.10.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via masterslider_pb and ms_slide Shortcodes
Master Slider <= 3.11.1 - Missing Authorization
Master Slider – Responsive Touch Slider <= 3.10.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via ms_layer Shortcode
Master Slider – Responsive Touch Slider <= 3.10.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via ms_slider Shortcode
Master Slider <= 3.10.0 - Authenticated (Admin+) Stored Cross-Site Scripting
Master Slider <= 3.10.0 - Reflected Cross-Site Scripting
Master Slider – Responsive Touch Slider <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via ms_layer Shortcode
Master Slider - Responsive Touch Slider <= 3.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Master Slider – Responsive Touch Slider <= 3.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Master Slider <= 3.9.5 - Unauthenticated PHP Object Injection
Master Slider – Responsive Touch Slider <= 3.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
Master Slider - Responsive Touch Slider <= 3.9.10 - Cross-Site Request Forgery via process_bulk_action
Master Slider – Responsive Touch Slider <= 3.9.9 - Authenticated(Editor+) Stored Cross-Site Scripting via slider callback
Master Slider – Responsive Touch Slider <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting
Master Slider <= 3.7.0 - Authenticated Stored Cross-Site Scripting
Master Slider <= 2.7.1 - Cross-Site Scripting
Master Slider - Responsive Touch Slider <= 2.5.1 - Authenticated Blind SQL Injection
Master Slider – Responsive Touch Slider Release Timeline
Master Slider – Responsive Touch Slider Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Master Slider – Responsive Touch Slider Attack Surface
AJAX Handlers 5
Shortcodes 9
WordPress Hooks 53
Maintenance & Trust
Master Slider – Responsive Touch Slider Maintenance & Trust
Maintenance Signals
Community Trust
Master Slider – Responsive Touch Slider Alternatives
Ovation Elements
ovation-elements
Transform your site with captivating sliders. Perfect for beginners and advanced users. Create and customize with our ultimate slider plugin.
Slider by webxapp – Responsive Image Slider for WordPress
slider-by-webxapp
The best WordPress slider plugin. Responsive slider builder that helps you create a beautiful image slideshows with just a few clicks.
Shader Spiral Carousel
shader-spiral-carousel
A lightweight, responsive multimedia spiral carousel powered by Three.js and custom shaders—smooth 3D transitions
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider
ml-slider
Slider, gallery, carousel plugin for WordPress. Build your image slider, video slider, post slider, YouTube slider, or WooCommerce product slider.
Prime Slider – Addons for Elementor
bdthemes-prime-slider-lite
Create responsive sliders using Elementor for hero sections, posts, logos, images, products, testimonials, and more.
Master Slider – Responsive Touch Slider Developer Profile
6 plugins · 310K total installs
How We Detect Master Slider – Responsive Touch Slider
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/master-slider/admin/assets/css/master-slider-admin.css/wp-content/plugins/master-slider/admin/assets/js/master-slider-admin.js/wp-content/plugins/master-slider/public/assets/css/masterslider.css/wp-content/plugins/master-slider/public/assets/css/masterslider-icon.css/wp-content/plugins/master-slider/public/assets/js/masterslider.min.js/wp-content/plugins/master-slider/admin/assets/js/master-slider-admin.js/wp-content/plugins/master-slider/public/assets/js/masterslider.min.js/wp-content/plugins/master-slider/admin/assets/css/master-slider-admin.css?ver=/wp-content/plugins/master-slider/admin/assets/js/master-slider-admin.js?ver=/wp-content/plugins/master-slider/public/assets/css/masterslider.css?ver=/wp-content/plugins/master-slider/public/assets/css/masterslider-icon.css?ver=/wp-content/plugins/master-slider/public/assets/js/masterslider.min.js?ver=HTML / DOM Fingerprints
master-sliderms-containerms-slides-container<!-- Master Slider -->data-mastersliderMasterSlider