CVE-2018-5374: Slidervilla Dbox Slider
High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.
The Dbox 3D Slider Lite plugin through 1.2.2 for WordPress has SQL Injection via settings\sliders.php (current_slider_id parameter).
Affected products
- Slidervilla Dbox Slider: up to and including 1.2.2
Published 2018-01-12. Last modified 2026-06-17.