Meta Slider and Carousel with Lightbox Security & Risk Analysis

wordpress.org/plugins/meta-slider-and-carousel-with-lightbox

Add a gallery meta box in your post, page and create a Image gallery menu tab. Display with a lightbox. Also work with Gutenberg shortcode block.

5K active installs v2.0.7 PHP + WP 4.0+ Updated Nov 12, 2025
frontend-gallery-carouselfrontend-gallery-slidergallery-slidermeta-gallery-image-carouselmeta-gallery-image-slider
99
A · Safe
CVEs total2
Unpatched0
Last CVESep 25, 2024
Safety Verdict

Is Meta Slider and Carousel with Lightbox Safe to Use in 2026?

Generally Safe

Score 99/100

Meta Slider and Carousel with Lightbox has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

2 known CVEsLast CVE: Sep 25, 2024Updated 6mo ago
Risk Assessment

The plugin "meta-slider-and-carousel-with-lightbox" v2.0.7 exhibits a generally good security posture with several positive indicators. The static analysis reveals a small attack surface with no apparent unprotected entry points. The code demonstrates strong practices regarding SQL queries, utilizing prepared statements exclusively, and a high percentage of properly escaped output. Furthermore, the presence of numerous nonce and capability checks suggests an awareness of common WordPress security vulnerabilities. However, the presence of the `unserialize` dangerous function is a notable concern, as it can be a vector for remote code execution if not handled with extreme caution and strict input validation. The vulnerability history, while currently showing no unpatched issues, indicates a pattern of medium-severity Cross-Site Scripting and Cross-Site Request Forgery vulnerabilities in the past. This suggests that while the developers address issues, these types of flaws have been present, warranting continued vigilance and thorough security testing. Overall, the plugin has strengths in its implementation of security best practices, but the `unserialize` function and past vulnerability patterns necessitate careful monitoring and patching.

Key Concerns

  • Use of 'unserialize' dangerous function
  • Past medium severity XSS & CSRF vulnerabilities
Vulnerabilities
2 published

Meta Slider and Carousel with Lightbox Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-47307medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Meta slider and carousel with lightbox <= 2.0.1 - Authenticated (Author+) Stored Cross-Site Scripting

Sep 25, 2024 Patched in 2.0.2 (8d)
CVE-2023-25703medium · 5.4Cross-Site Request Forgery (CSRF)

Meta Slider and Carousel with Lightbox <= 1.6.2 - Cross-Site Request Forgery

Feb 15, 2023 Patched in 1.7 (342d)
Version History

Meta Slider and Carousel with Lightbox Release Timeline

v2.0.8
v2.0.7Current
v2.0.6
v2.0.5
v2.0.4
v2.0.3
v2.0.2
v2.0.11 CVE
Code Analysis
Analyzed Mar 16, 2026

Meta Slider and Carousel with Lightbox Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
12
301 escaped
Nonce Checks
8
Capability Checks
3
File Operations
1
External Requests
1
Bundled Libraries
0

Dangerous Functions Found

unserialize$info = @unserialize($data);wpos-analytics\includes\class-anylc-admin.php:670

Output Escaping

96% escaped313 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<solutions-features> (includes\admin\settings\solution-features\solutions-features.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Meta Slider and Carousel with Lightbox Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 2

authwp_ajax_wp_igsp_get_attachment_edit_formincludes\admin\class-wp-igsp-admin.php:43
authwp_ajax_wp_igsp_save_attachment_dataincludes\admin\class-wp-igsp-admin.php:46

Shortcodes 2

[meta_gallery_carousel] includes\shortcode\wp-igsp-meta-gallery-carousel.php:139
[meta_gallery_slider] includes\shortcode\wp-igsp-meta-gallery-slider.php:136
WordPress Hooks 30
actionplugins_loadedfrontend-gallery-slider.php:87
actionupdate_option_active_pluginsfrontend-gallery-slider.php:121
actionadmin_noticesfrontend-gallery-slider.php:183
actionadmin_menuincludes\admin\class-wp-igsp-admin.php:19
actionadd_meta_boxesincludes\admin\class-wp-igsp-admin.php:22
actionsave_postincludes\admin\class-wp-igsp-admin.php:25
actionadmin_initincludes\admin\class-wp-igsp-admin.php:28
filterpost_row_actionsincludes\admin\class-wp-igsp-admin.php:37
actionadmin_footerincludes\admin\class-wp-igsp-admin.php:40
actioninitincludes\admin\supports\gutenberg-block.php:146
actionenqueue_block_assetsincludes\admin\supports\gutenberg-block.php:155
actionenqueue_block_editor_assetsincludes\admin\supports\gutenberg-block.php:179
filterblock_categories_allincludes\admin\supports\gutenberg-block.php:200
actionadmin_enqueue_scriptsincludes\class-wp-igsp-script.php:19
actionwp_enqueue_scriptsincludes\class-wp-igsp-script.php:22
actioninitincludes\wp-igsp-post-types.php:52
filterpost_updated_messagesincludes\wp-igsp-post-types.php:82
actionadmin_menuwpos-analytics\includes\class-anylc-admin.php:38
actionadmin_menuwpos-analytics\includes\class-anylc-admin.php:41
actionadmin_initwpos-analytics\includes\class-anylc-admin.php:44
actionadmin_noticeswpos-analytics\includes\class-anylc-admin.php:47
actionadmin_footerwpos-analytics\includes\class-anylc-admin.php:50
actionwp_loadedwpos-analytics\includes\class-anylc-admin.php:53
actioninitwpos-analytics\includes\class-anylc-admin.php:56
filtercron_scheduleswpos-analytics\includes\class-anylc-admin.php:59
actionwpos_monthly_cron_hookwpos-analytics\includes\class-anylc-admin.php:62
actionrest_api_initwpos-analytics\includes\class-anylc-admin.php:65
actionadmin_enqueue_scriptswpos-analytics\includes\class-anylc-script.php:20
actionactivated_pluginwpos-analytics\wpos-analytics.php:244
actionplugins_loadedwpos-analytics\wpos-analytics.php:258

Scheduled Events 1

wpos_monthly_cron_hook
Maintenance & Trust

Meta Slider and Carousel with Lightbox Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 12, 2025
PHP min version
Downloads230K

Community Trust

Rating96/100
Number of ratings17
Active installs5K
Developer Profile

Meta Slider and Carousel with Lightbox Developer Profile

Essential Plugin

33 plugins · 204K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
212 days
View full developer profile
Detection Fingerprints

How We Detect Meta Slider and Carousel with Lightbox

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/meta-slider-and-carousel-with-lightbox/assets/css/slick.css/wp-content/plugins/meta-slider-and-carousel-with-lightbox/assets/css/magnific-popup.css/wp-content/plugins/meta-slider-and-carousel-with-lightbox/assets/css/wp-igsp-admin.css/wp-content/plugins/meta-slider-and-carousel-with-lightbox/assets/css/wp-igsp-public.css/wp-content/plugins/meta-slider-and-carousel-with-lightbox/assets/js/slick.min.js/wp-content/plugins/meta-slider-and-carousel-with-lightbox/assets/js/jquery.magnific-popup.min.js/wp-content/plugins/meta-slider-and-carousel-with-lightbox/assets/js/wp-igsp-public.js/wp-content/plugins/meta-slider-and-carousel-with-lightbox/assets/js/wp-igsp-admin.js+1 more
Script Paths
/wp-content/plugins/meta-slider-and-carousel-with-lightbox/assets/js/slick.min.js/wp-content/plugins/meta-slider-and-carousel-with-lightbox/assets/js/jquery.magnific-popup.min.js/wp-content/plugins/meta-slider-and-carousel-with-lightbox/assets/js/wp-igsp-public.js/wp-content/plugins/meta-slider-and-carousel-with-lightbox/assets/js/wp-igsp-admin.js/wp-content/plugins/meta-slider-and-carousel-with-lightbox/assets/js/blocks.build.js
Version Parameters
/wp-content/plugins/meta-slider-and-carousel-with-lightbox/assets/css/slick.css?ver=/wp-content/plugins/meta-slider-and-carousel-with-lightbox/assets/css/magnific-popup.css?ver=/wp-content/plugins/meta-slider-and-carousel-with-lightbox/assets/css/wp-igsp-admin.css?ver=/wp-content/plugins/meta-slider-and-carousel-with-lightbox/assets/css/wp-igsp-public.css?ver=/wp-content/plugins/meta-slider-and-carousel-with-lightbox/assets/js/slick.min.js?ver=/wp-content/plugins/meta-slider-and-carousel-with-lightbox/assets/js/jquery.magnific-popup.min.js?ver=/wp-content/plugins/meta-slider-and-carousel-with-lightbox/assets/js/wp-igsp-public.js?ver=/wp-content/plugins/meta-slider-and-carousel-with-lightbox/assets/js/wp-igsp-admin.js?ver=/wp-content/plugins/meta-slider-and-carousel-with-lightbox/assets/js/blocks.build.js?ver=

HTML / DOM Fingerprints

CSS Classes
wp-igsp-slider-wrapwp-igsp-carousel-wrapwp-igsp-popup-link
HTML Comments
<!-- WPOS Analytics Starts --><!-- WPOS Analytics Ends --><!-- Plugin Wpos Analytics Data Starts --><!-- Plugin Wpos Analytics Data Ends -->
Data Attributes
data-gallery-iddata-mfp-src
JS Globals
Wp_Igspf_Block
Shortcode Output
[wp_gallery_slider][wp_gallery_carousel]
FAQ

Frequently Asked Questions about Meta Slider and Carousel with Lightbox