What the vulnerability does
01Description
Missing Authorization vulnerability in Plugin Devs Product Carousel Slider for Elementor ecommerce-product-carousel-slider-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Carousel Slider for Elementor: from n/a through <= 2.1.3.
Explanation of Vulnerability in Simple Terms
02Summary
Product Carousel Slider for Elementor versions 2.1.3 and earlier lack proper authorization checks. A logged-in user can trigger a denial-of-service condition by performing specific actions that require user interaction. The vulnerability does not affect data confidentiality or integrity, only site availability.
What an attacker can do
03Attacker Capabilities
A logged-in user can make the site temporarily unavailable or unresponsive.
Potential impact on your site
04Site Impact
Site availability may be disrupted if a user account is compromised or a user is socially engineered.
Conditions required to exploit
05Prerequisites
Attacker must have a user account on the site and trick a user into clicking a malicious link or visiting a crafted page.
Key dates
06Disclosure timeline
September 5, 2025
CVE published
May 13, 2026
Record updated