What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Patel Post Carousel & Slider post-types-carousel-slider allows Reflected XSS.This issue affects Post Carousel & Slider: from n/a through <= 1.0.4.
Explanation of Vulnerability in Simple Terms
02Summary
Post Carousel & Slider versions 1.0.4 and earlier contain a cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts that execute in visitors' browsers when they view affected carousel or slider content. The vulnerability requires user interaction—typically a victim clicking a malicious link—and can affect other users on the site. This allows theft of session cookies, account hijacking, or defacement.
What an attacker can do
03Attacker Capabilities
Inject malicious JavaScript that runs in visitors' browsers, stealing cookies or hijacking accounts.
Potential impact on your site
04Site Impact
Visitors' accounts and sessions can be compromised; site reputation and user trust at risk.
Conditions required to exploit
05Prerequisites
No authentication required. Victim must click a malicious link or visit a page with injected content.
Key dates
06Disclosure timeline
January 15, 2025
CVE published
May 11, 2026
Record updated