plugin

Post Carousel Vulnerabilities

11 known security issues reported for the Post Carousel WordPress plugin. Most recent disclosed Apr 13, 2026.

2 high 3 medium

Running Post Carousel on your site? Check whether your installed version is affected.

Scan your site free

Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts <= 3.0.12 - Authenticated (Administrator+) PHP Object Injection

high

The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.12 via deserialization of untrusted input in the import_shortcodes() function. This makes it possible for authenticated attackers, with Ad...

CVSS:
7.2
Affected:
up to 3.0.12
Fixed in:
3.0.13
Disclosed:
Apr 13, 2026

CVE-2026-3017 on NVD →

Smart Post Show <= 3.0.0 - Authenticated (Editor+) Stored Cross-Site Scripting via Pagination Color

medium

The Smart Post Show plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pagination Color setting in all versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access, to inject arbitrary...

CVSS:
5.5
Affected:
up to 3.0.0
Fixed in:
3.0.1
Disclosed:
Oct 8, 2024

CVE-2024-8187 on NVD →

Post Grid, Post Carousel, & List Category Posts <= 2.4.27 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The Smart Post Show – Post Grid, Post Carousel, Post Slider, Post Timeline, Post Table, and List Category Posts, Latest Posts, Recent Posts, Popular Posts and More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.27 due to insufficient input...

CVSS:
4.4
Affected:
up to 2.4.27
Fixed in:
2.4.28
Disclosed:
Apr 4, 2024

CVE-2024-3996 on NVD →

Smart Post Show – Post Grid, Post Carousel, Post Slider, Post Timeline, Post Table, and List Category Posts, Latest Posts, Recent Posts, Popular Posts and More [post-carousel] < 2.4.19

unknown

[en] The Post Grid, Post Carousel, & List Category Posts WordPress plugin before 2.4.19 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Affected:
up to 2.4.19
Fixed in:
2.4.19
Disclosed:
Jan 30, 2023

CVE-2023-0097 on NVD →

Post Grid, Post Carousel, & List Category Posts <= 2.4.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Post Grid, Post Carousel, & List Category Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 2.4.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated atta...

CVSS:
6.4
Affected:
up to 2.4.18
Fixed in:
2.4.19
Disclosed:
Jan 6, 2023

CVE-2023-0097 on NVD →

Smart Post Show – Post Grid, Post Carousel, Post Slider, Post Timeline, Post Table, and List Category Posts, Latest Posts, Recent Posts, Popular Posts and More [post-carousel] < 2.3.5

unknown

Update the WordPress Post Grid, Post Carousel, & List Category Posts – by Smart Post Show plugin to the latest available version (at least 2.3.5). WPScan discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Post Grid, Post Carousel, & List Category Posts – by Smart Post Show Plugin....

Affected:
up to 2.3.5
Fixed in:
2.3.5
Disclosed:
Jan 6, 2023

Post Carousel < 2.3.5 - Missing Capabilities Check

high

The Post Carousel plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on multiple functions in versions up to, and including, 2.3.4. This makes it possible for attackers to improperly access administrative actions.

CVSS:
7.3
Affected:
up to 2.3.5
Fixed in:
2.3.5
Disclosed:
Aug 16, 2021

Smart Post Show – Post Grid, Post Carousel, Post Slider, Post Timeline, Post Table, and List Category Posts, Latest Posts, Recent Posts, Popular Posts and More [post-carousel] < 2.3.5

unknown

The Post Carousel plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on multiple functions in versions up to, and including, 2.3.4. This makes it possible for attackers to improperly access administrative actions.

Affected:
up to 2.3.5
Fixed in:
2.3.5
Disclosed:
Aug 16, 2021

Smart Post Show – Post Grid, Post Carousel, Post Slider, Post Timeline, Post Table, and List Category Posts, Latest Posts, Recent Posts, Popular Posts and More [post-carousel] < 2.3.5

unknown

The plugin did not properly check for CSRF in two of its AJAX actions, allowing them to be bypassed. Furthermore, other actions which should only be accessible to admins were missing capability check (but had CSRF checks), and the spf-reset action did not validate that the actions to be delete belong to the plugin. Var...

Affected:
up to 2.3.5
Fixed in:
2.3.5

Smart Post Show – Post Grid, Post Carousel, Post Slider, Post Timeline, Post Table, and List Category Posts, Latest Posts, Recent Posts, Popular Posts and More [post-carousel] < 2.4.28

unknown
Affected:
up to 2.4.28
Fixed in:
2.4.28

CVE-2024-3996 on NVD →

Smart Post Show – Post Grid, Post Carousel, Post Slider, Post Timeline, Post Table, and List Category Posts, Latest Posts, Recent Posts, Popular Posts and More [post-carousel] < 3.0.1

unknown
Affected:
up to 3.0.1
Fixed in:
3.0.1

CVE-2024-8187 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database