
WP Contact Slider – Contact Form Slider Widget Security & Risk Analysis
wordpress.org/plugins/wp-contact-sliderHelps you to show slide out contact form to display CF7, Gravity forms, Ninja Forms, WP Forms, display random text/HTML and support some other forms.
Is WP Contact Slider – Contact Form Slider Widget Safe to Use in 2026?
Generally Safe
Score 99/100WP Contact Slider – Contact Form Slider Widget has a strong security track record. Known vulnerabilities have been patched promptly.
The wp-contact-slider plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices in its handling of SQL queries, exclusively using prepared statements, and boasts a high percentage of properly escaped output. The plugin also incorporates nonce and capability checks, suggesting an awareness of common WordPress security mechanisms. However, the presence of two AJAX handlers without authentication checks presents a significant concern, creating a direct attack surface that could be exploited by unauthenticated users. The vulnerability history reveals two medium-severity CVEs, both related to Cross-site Scripting, with the last one occurring in late 2022. While no currently unpatched vulnerabilities are reported, this history indicates a recurring pattern of input validation or output sanitization issues that attackers have successfully exploited in the past. The lack of taint analysis results makes it difficult to assess the sanitization of dynamic paths, but the identified AJAX vulnerabilities are concrete points of concern.
Key Concerns
- Unprotected AJAX handlers
- Medium severity CVE history (2)
- Bundled outdated library (Freemius v1.0)
WP Contact Slider – Contact Form Slider Widget Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP Contact Slider <= 2.4.7 - Authenticated (Administrator+) Stored Cross-Site Scripting
WP Contact Slider <= 2.4.6 - Stored Cross-Site Scripting
WP Contact Slider – Contact Form Slider Widget Code Analysis
Bundled Libraries
Output Escaping
WP Contact Slider – Contact Form Slider Widget Attack Surface
AJAX Handlers 3
Shortcodes 1
WordPress Hooks 43
Maintenance & Trust
WP Contact Slider – Contact Form Slider Widget Maintenance & Trust
Maintenance Signals
Community Trust
WP Contact Slider – Contact Form Slider Widget Alternatives
Autopreenchimento de endereço em formulários
cf7-cep-autofill
Preenchimento automático de campos de endereço baseado no CEP informado.
WP Mautic Form Integrator
wp-mautic-form-integrator
Mautic is a marketing automation software and WP Mautic Form Integrator plugin is a bridge between Mautic and several highly used form plugins.
Proweblook Phone Validator
proweblook-phone-validator
With the Proweblook Phone Validator plugin you can easily verify if a phone number is really valid and callable (https://proweblook.com).
WPGContacts
wpgcontacts
Send your Contact Form 7 data directly to your Google Contacts spreadsheet.
Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms
cf7-mailchimp
Send Contact Form 7, WPforms, Elementor, Ninja Forms, CRM Perks Forms and many other contact form submissions to Mailchimp.
WP Contact Slider – Contact Form Slider Widget Developer Profile
84 plugins · 1.4M total installs
How We Detect WP Contact Slider – Contact Form Slider Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-contact-slider/inc/wpcs_admin_functions.php/wp-content/plugins/wp-contact-slider/inc/wpcs_slider.php/wp-content/plugins/wp-contact-slider/inc/wpcs_frontend_functions.php/wp-content/plugins/wp-contact-slider/inc/wpcs_enque_styles.php/wp-content/plugins/wp-contact-slider/inc/wpcs_enque_scripts.php/wp-content/plugins/wp-contact-slider/inc/wpcs_bundle_menu.php/wp-content/plugins/wp-contact-slider/freemius/start.phpHTML / DOM Fingerprints
wpcs-contact-form-sliderdata-wpcs-slider-iddata-wpcs-slider-settingswpcs_slider_data/wp-json/wpcs/v1/get-slider-data[wp_contact_slider id=