The Post Slider and Post Carousel with Post Vertical Scrolling Widget WordPress plugin before 3.2.10 does not validate and escape some of its Widget options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
History

Thu, 05 Jun 2025 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Infornweb
Infornweb post Slider And Post Carousel
Weaknesses CWE-79
CPEs cpe:2.3:a:infornweb:post_slider_and_post_carousel:*:*:*:*:*:wordpress:*:*
Vendors & Products Infornweb
Infornweb post Slider And Post Carousel

Tue, 03 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 03 Jun 2025 06:15:00 +0000

Type Values Removed Values Added
Description The Post Slider and Post Carousel with Post Vertical Scrolling Widget WordPress plugin before 3.2.10 does not validate and escape some of its Widget options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Title Post Slider and Carousel with Widget < 3.2.10 - Admin+ Stored XSS
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-06-03T06:00:17.565Z

Updated: 2025-06-03T15:24:55.420Z

Reserved: 2025-05-12T08:21:53.822Z

Link: CVE-2025-4567

cve-icon Vulnrichment

Updated: 2025-06-03T15:24:38.355Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-03T06:15:27.983

Modified: 2025-06-05T14:09:17.020

Link: CVE-2025-4567

cve-icon Redhat

No data.