cleantalk
Vulnerabilities and Security Researches

Custom Post Carousels with Owl, CVE-2025-5125

CVE, Research URL

CVE-2025-5125

Published on
Jun 20, 2025
Research Description
The Custom Post Carousels with Owl WordPress plugin before 1.4.12 uses the featherlight library and makes use of the data-featherlight attribute without sanitizing before using it.
Affected versions
Min -, max 1.4.12.
Status
vulnerable