cleantalk
Vulnerabilities and Security Researches

Divi Carousel Lite – Image Carousel and Logo Carousel, 72b75bc03ad56a2650cd6b1c19f27ecbad3dfed2

Published on
Jul 19, 2023
Research Description
Divi Carousel Maker [wow-carousel-for-divi-lite] < 1.2.12 WordPress Divi Carousel Lite Plugin <= 1.2.11 is vulnerable to Cross Site Scripting (XSS) Update the WordPress Divi Carousel Lite plugin to the latest available version. Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Divi Carousel Lite Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.2.12.
Affected versions
Min -, max 1.2.12.
Status
vulnerable