Vertical scroll slideshow gallery v2 Security & Risk Analysis

wordpress.org/plugins/vertical-scroll-slideshow-gallery-v2

Vertical scroll slideshow gallery plugin will create the vertical scrolling image slideshow gallery on the wordpress widget.

20 active installs v9.1 PHP + WP 3.4+ Updated Dec 1, 2022
galleryimagesscrollslideshowvertical
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEAug 15, 2025
Safety Verdict

Is Vertical scroll slideshow gallery v2 Safe to Use in 2026?

Use With Caution

Score 63/100

Vertical scroll slideshow gallery v2 has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Aug 15, 2025Updated 3yr ago
Risk Assessment

The plugin 'vertical-scroll-slideshow-gallery-v2' v9.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices with a high percentage of SQL queries using prepared statements and a limited attack surface with only one shortcode entry point. The absence of file operations and external HTTP requests further mitigates certain attack vectors. However, concerns arise from the low percentage of properly escaped output (39%), which can leave the application vulnerable to cross-site scripting (XSS) attacks. The presence of one unpatched medium severity CVE related to SQL injection, despite the general use of prepared statements, is a significant concern and indicates a historical weakness in sanitizing inputs for SQL queries. This suggests that while the developers may be using prepared statements for most queries, there's a specific instance or type of input that still allows for injection, and this has not been addressed.

Overall, while the plugin has strengths in its limited attack surface and proper SQL handling in most cases, the persistent SQL injection vulnerability and the high rate of unescaped output represent significant risks. The vulnerability history, particularly the single medium CVE which remains unpatched, suggests a potential lack of rigorous security testing or a delay in addressing reported issues. Users should be cautious due to the unpatched SQL injection vulnerability and the potential for XSS due to insufficient output escaping.

Key Concerns

  • Unpatched medium severity CVE
  • Low percentage of properly escaped output
Vulnerabilities
1

Vertical scroll slideshow gallery v2 Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-49897medium · 6.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Vertical scroll slideshow gallery v2 <= 9.1 - Authenticated (Contributor+) SQL Injection

Aug 15, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Vertical scroll slideshow gallery v2 Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
20 prepared
Unescaped Output
38
24 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

95% prepared21 total queries

Output Escaping

39% escaped62 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<image-management-show> (pages\image-management-show.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Vertical scroll slideshow gallery v2 Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[vertical-scroll-slideshow-gallery] vertical-scroll-slideshow-gallery-v2.php:25
WordPress Hooks 4
actionadmin_menuvertical-scroll-slideshow-gallery-v2.php:367
actionplugins_loadedvertical-scroll-slideshow-gallery-v2.php:368
actionwidgets_initvertical-scroll-slideshow-gallery-v2.php:371
actionadmin_enqueue_scriptsvertical-scroll-slideshow-gallery-v2.php:372
Maintenance & Trust

Vertical scroll slideshow gallery v2 Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedDec 1, 2022
PHP min version
Downloads15K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Vertical scroll slideshow gallery v2 Developer Profile

gopiplus

52 plugins · 19K total installs

76
trust score
Avg Security Score
83/100
Avg Patch Time
70 days
View full developer profile
Detection Fingerprints

How We Detect Vertical scroll slideshow gallery v2

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vertical-scroll-slideshow-gallery-v2/style.css/wp-content/plugins/vertical-scroll-slideshow-gallery-v2/script.js
Script Paths
/wp-content/plugins/vertical-scroll-slideshow-gallery-v2/script.js
Version Parameters
vertical-scroll-slideshow-gallery-v2/style.css?ver=vertical-scroll-slideshow-gallery-v2/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
hsas-widget
HTML Comments
<!-- Vertical scroll slideshow gallery v2 -->
Data Attributes
id="vs2_main"id="vs2_first"id="vs2_second"id="vs2_main2"id="vs2_first2"id="vs2_second2"
JS Globals
vs2_slideimagesvs2_scrollerwidthvs2_scrollerheightvs2_pausebetweenimagesiedom
Shortcode Output
[vertical-scroll-slideshow-gallery group=No records found, please check your short code
FAQ

Frequently Asked Questions about Vertical scroll slideshow gallery v2