The Logo Slider – Logo Carousel, Client Logo Slider & Brand Showcase for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lgx_tooltip_position' parameter in all versions up to, and including, 5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 3,283 live websites that are affected by CVE-2026-13247.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 3,283 live websites (100% of Logo Slider Wp install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 1 versions ( 100% of all versions) |
| 872 websites | |
| 244 websites | |
| 217 websites | |
| 169 websites | |
| 166 websites | |
| 155 websites | |
| 132 websites | |
| 122 websites | |
| 121 websites | |
| 82 websites |
| .com | 1,236 websites |
| .org | 180 websites |
| .nl | 113 websites |
| .co.uk | 112 websites |
| .pl | 108 websites |
| .de | 106 websites |
| .it | 90 websites |
| .com.au | 71 websites |
| .fr | 70 websites |
| .eu | 47 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.com | **,*** | ||
| **********.org | ***,*** | ||
| **********.com | ***,*** | ||
| ***********.com | ***,*** | ||
| *************.com | ***,*** | ||
| ***.nz | ***,*** | ||
| *******.com | ***,*** | ||
| ***.**.nz | ***,*** | ||
| *******************.com | ***,*** | ||
| **********.no | ***,*** |
FAQ