CVE-2016-10974: Tonjoostudio Fluid-Responsive-Slideshow

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has frs_save CSRF with resultant stored XSS.

Affected products

  • Tonjoostudio Fluid-Responsive-Slideshow: before 2.2.7 (fixed in 2.2.7)

Published 2019-09-17. Last modified 2026-06-17.