Pricing
Case studies
Login
Start trial
Slider Revolution
ThemePunch
Developer
N/A
Latest version
N/A
Installations
N/A
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
18 patched
4 Mitigation rules
Authenticated (Author+) Stored Cross-Site Scripting via Add Layer class, id, and title Attributes vulnerability
<= 6.7.10
02/02/2026
Authenticated (Contributor+) Stored Cross-Site Scripting via Elementor wrapperid and zindex vulnerability
<= 6.7.10
02/02/2026
Missing Authorization to Authenticated (Contributor+) Arbitrary File Read vulnerability
<= 6.7.37
09/10/2025
Authenticated (Contributor+) Arbitrary File Read via 'used_svg' and 'used_images' vulnerability
<= 6.7.36
29/08/2025
Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload vulnerability
<= 6.7.18
01/10/2024
Cross Site Scripting (XSS) vulnerability
<= 6.7.13
28/06/2024
Cross Site Scripting (XSS) vulnerability
< 6.7.11
28/05/2024
Unauthenticated Broken Access Control vulnerability
< 6.7.0
28/05/2024
Authenticated (Author+) Stored Cross-Site Scripting via htmltag Parameter vulnerability
<= 6.7.7
01/05/2024
Authenticated (Author+) Stored Cross-Site Scripting vulnerability
<= 6.6.20
09/04/2024
Author+ Arbitrary File Upload vulnerability
<= 6.6.15
14/11/2023
Cross Site Scripting (XSS) vulnerability
<= 6.6.14
14/11/2023
Author+ Remote Code Execution Vulnerability
<= 6.6.12
30/05/2023
XSS
<= 4.2.2
30/06/2015
Multiple Vulnerabilities
<= 3.0.95
30/06/2015
File Upload and Execute
<= 3.0.95
08/05/2015
Arbitrary File Download
< 4.2
30/03/2015
Shell Upload Exploit
<= 3.0.95
26/11/2014