What the vulnerability does
01Description
Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions.
Explanation of Vulnerability in Simple Terms
The Custom links feature in Elementor Image Carousel allows high-privilege users to inject malicious scripts into carousel links. When a site visitor views the carousel, the injected script runs in their browser, potentially stealing session data or performing actions on their behalf. A site administrator must enable and configure the custom links feature for this vulnerability to be exploitable.
What an attacker can do
Inject malicious scripts that run when site visitors view the image carousel.
Potential impact on your site
Visitor sessions and data at risk if an admin account is compromised or a malicious admin is present.
Conditions required to exploit
High-privilege account (e.g., administrator) and the victim must view the affected carousel.
Key dates
External resources
Related vulnerabilities