cleantalk
Vulnerabilities and Security Researches

Post Slider and Post Carousel with Post Vertical Scrolling Widget – A Responsive Post Slider, CVE-2025-4567

CVE, Research URL

CVE-2025-4567

Published on
Jun 03, 2025
Research Description
The Post Slider and Post Carousel with Post Vertical Scrolling Widget WordPress plugin before 3.2.10 does not validate and escape some of its Widget options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected versions
Min -, max 3.2.10.
Status
vulnerable