WPB Category Slider for WooCommerce – Product Categories Carousel & Grid Security & Risk Analysis

wordpress.org/plugins/wpb-woocommerce-category-slider

Display WooCommerce product categories in responsive sliders and grids to boost navigation, engagement, and product discovery.

800 active installs v1.7.2 PHP + WP 5.0+ Updated Mar 13, 2026
category-sliderproductproduct-categoryproduct-category-sliderwoocommerce-category-slider
76
B · Generally Safe
CVEs total1
Unpatched1
Last CVEJun 27, 2025
Safety Verdict

Is WPB Category Slider for WooCommerce – Product Categories Carousel & Grid Safe to Use in 2026?

Mostly Safe

Score 76/100

WPB Category Slider for WooCommerce – Product Categories Carousel & Grid is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Jun 27, 2025Updated 21d ago
Risk Assessment

The "wpb-woocommerce-category-slider" plugin v1.7.2 exhibits a mixed security posture. While the static analysis indicates a relatively small attack surface with no unprotected entry points and a high percentage of SQL queries using prepared statements, several concerning code signals and a significant vulnerability history raise red flags. The presence of the dangerous `create_function` is a known risk, and the 100% usage of prepared statements for SQL is positive, but the output escaping is not perfect at 81%, leaving room for potential cross-site scripting (XSS) vulnerabilities if sensitive data is not handled carefully. The taint analysis, however, shows no detected flows, which is a positive indicator for that specific analysis method.

The vulnerability history is a major concern. With one known high-severity CVE related to Improper Control of Filename for Include/Require Statement in PHP Program (PHP Remote File Inclusion), and it being currently unpatched, this presents a critical risk. The recurrence of this vulnerability type suggests a persistent coding flaw that attackers could exploit for remote code execution. The last vulnerability being in the future (2025) might be a data anomaly, but the fact that there is an unpatched high-severity CVE in the present is undeniable. While the plugin has strengths in its limited attack surface and prepared SQL statements, the unpatched RFI vulnerability severely compromises its overall security, making it a high-risk option for deployment without immediate patching or mitigation.

Key Concerns

  • Unpatched High Severity CVE (RFI)
  • Dangerous function usage (create_function)
  • Output escaping is not 100%
Vulnerabilities
1

WPB Category Slider for WooCommerce – Product Categories Carousel & Grid Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2025-53281high · 7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

WPB Category Slider for WooCommerce <= 1.71 - Authenticated (Contributor+) Local File Inclusion

Jun 27, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

WPB Category Slider for WooCommerce – Product Categories Carousel & Grid Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
22
96 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_function$callback = create_function('', 'echo "' . str_replace( '"', '\"', $section['desc'] ) . '";');admin\settings\class.settings-api.php:108

Output Escaping

81% escaped118 total outputs
Attack Surface

WPB Category Slider for WooCommerce – Product Categories Carousel & Grid Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wpb-woo-category-slider] inc\wpb-wcs-shortcode.php:13
WordPress Hooks 24
actionadmin_enqueue_scriptsadmin\settings\class.settings-api.php:30
actionadmin_initadmin\settings\wpb-wcs-settings-config.php:14
actionadmin_menuadmin\settings\wpb-wcs-settings-config.php:15
actionproduct_cat_add_form_fieldsadmin\taxonomie-meta.php:15
actionproduct_cat_edit_form_fieldsadmin\taxonomie-meta.php:16
actionedited_product_catadmin\taxonomie-meta.php:17
actioncreate_product_catadmin\taxonomie-meta.php:18
filtermanage_edit-product_cat_columnsadmin\taxonomie-meta.php:19
filtermanage_product_cat_custom_columnadmin\taxonomie-meta.php:20
actionadmin_enqueue_scriptsadmin\taxonomie-meta.php:21
actionadmin_footeradmin\taxonomie-meta.php:206
actionwp_enqueue_scriptsinc\wpb-wcs-functions.php:31
actionwp_enqueue_scriptsinc\wpb-wcs-functions.php:38
actionadmin_enqueue_scriptsinc\wpb-wcs-functions.php:92
actionadmin_menuinc\wpb-wcs-functions.php:131
filteradmin_footer_textinc\wpb-wcs-functions.php:160
filtermanage_edit-product_cat_columnsinc\wpb-wcs-functions.php:167
filtermanage_edit-product_cat_sortable_columnsinc\wpb-wcs-functions.php:168
filtermanage_product_cat_custom_columninc\wpb-wcs-functions.php:169
actionadmin_noticesmain.php:54
actionadmin_noticesmain.php:84
actionadmin_initmain.php:85
actionwp_dashboard_setupmain.php:86
actionplugins_loadedmain.php:94
Maintenance & Trust

WPB Category Slider for WooCommerce – Product Categories Carousel & Grid Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 13, 2026
PHP min version
Downloads38K

Community Trust

Rating82/100
Number of ratings9
Active installs800
Developer Profile

WPB Category Slider for WooCommerce – Product Categories Carousel & Grid Developer Profile

WPBean

25 plugins · 40K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
20 days
View full developer profile
Detection Fingerprints

How We Detect WPB Category Slider for WooCommerce – Product Categories Carousel & Grid

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpb-woocommerce-category-slider/assets/css/frontend.min.css/wp-content/plugins/wpb-woocommerce-category-slider/assets/js/frontend.min.js/wp-content/plugins/wpb-woocommerce-category-slider/admin/css/admin.css
Script Paths
/wp-content/plugins/wpb-woocommerce-category-slider/assets/js/frontend.min.js
Version Parameters
/wp-content/plugins/wpb-woocommerce-category-slider/assets/css/frontend.min.css?ver=/wp-content/plugins/wpb-woocommerce-category-slider/assets/js/frontend.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpb-category-sliderwpb-category-slider-wrapper
Data Attributes
data-slide-itemsdata-slide-margindata-slide-navdata-slide-dotsdata-slide-loopdata-slide-autoplay+3 more
Shortcode Output
[wpb_category_slider]
FAQ

Frequently Asked Questions about WPB Category Slider for WooCommerce – Product Categories Carousel & Grid