CVE-2024-3285

Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Slideshows <= 3.70.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via metaslider Shortcode

The Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Slideshows plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'metaslider' shortcode in all versions up to, and including, 3.70.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 44,239 live websites that are affected by CVE-2024-3285.

Run a Free Instant Scan




Affected Software

Product  MetaSlider for WordPress
Category Wordpress Plugins
Vulnerable Domains44,239 live websites (34% of MetaSlider for WordPress install base)
Vulnerable Versions
  • from 0 through 3.70
Vulnerable Versions Count114 versions ( 83% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Apr 11, 2024
  • Updated - Apr 8, 2026

Credits

  • wesley (finder)

Website Distribution by Country

Number of websites using CVE-2024-3285
United States7,838 websites



Japan8,317 websites
Germany3,917 websites
Russia2,577 websites
France2,202 websites
Italy1,819 websites
GB1,531 websites
Poland1,340 websites
Vietnam1,146 websites
Netherlands1,090 websites

Website Distribution by TLD

Number of websites using CVE-2024-3285
.com17,051 websites
.de2,518 websites
.jp2,376 websites
.ru2,141 websites
.org1,692 websites
.net1,279 websites
.it1,229 websites
.co.jp1,079 websites
.pl1,007 websites
.co.uk968 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-3285

Top websites that are affected by CVE-2024-3285. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.ru Russia**,***
**************.ca Canada**,***
*********.**.jp United States**,***
******.*******.**.jp Japan**,***
********.**.jp Japan**,***
****.************.org United States**,***
****************.org United States**,***
*****.it Italy**,***
*************.net United States**,***
************.com United States**,***
See full domain list

FAQ

CVE-2024-3285 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in MetaSlider for WordPress
A total of 44,239 websites have been identified as vulnerable to CVE-2024-3285, based on global website indexing conducted by WebTechSurvey.
The MetaSlider for WordPress is affected by the CVE-2024-3285 vulnerability.
MetaSlider for WordPress versions up to and including 3.70 are vulnerable to CVE-2024-3285.