plugin

Wp Carousel Free Vulnerabilities

7 known security issues reported for the Wp Carousel Free WordPress plugin. Most recent disclosed May 4, 2026.

1 high 6 medium

Running Wp Carousel Free on your site? Check whether your installed version is affected.

Scan your site free

WP Carousel Free <= 2.7.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-caption' Attribute

medium

The WP Carousel Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted fancybox `data-caption` attributes in all versions up to, and including, 2.7.10. This is due to the `fancybox-config.js` script reading the carousel container's `id` attribute directly from the DOM to construct a jQuery s...

CVSS:
6.4
Affected:
up to 2.7.10
Fixed in:
2.7.11
Disclosed:
May 4, 2026

CVE-2026-4665 on NVD →

Carousel, Slider, Gallery by WP Carousel <= 2.7.3 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Carousel, Slider, Gallery by WP Carousel – Image Carousel with Lightbox & Photo Gallery, Video Slider, Post Carousel & Post Grid, Product Carousel & Product Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 2.7.3 due to insufficient input sanit...

CVSS:
4.4
Affected:
up to 2.7.3
Fixed in:
2.7.4
Disclosed:
Jan 31, 2025

CVE-2024-13314 on NVD →

Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library

medium

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...

CVSS:
6.4
Affected:
up to 2.6.8
Fixed in:
2.6.9
Disclosed:
Dec 3, 2024

CVE-2024-5020 on NVD →

Carousel, Slider, Gallery by WP Carousel <= 2.6.8 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The Carousel, Slider, Gallery by WP Carousel – Image Carousel with Lightbox & Photo Gallery, Video Slider, Post Carousel & Post Grid, Product Carousel & Product Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 2.6.8 due to insufficient input sanit...

CVSS:
4.4
Affected:
up to 2.6.8
Fixed in:
2.6.9
Disclosed:
Oct 30, 2024

CVE-2024-4002 on NVD →

Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 - Authenticated (Admin+) PHP Object Injection

high

The plugin is vulnerable to PHP Object Injection in versions up to and including, 2.6.3 via deserialization of untrusted input in the import function via the 'shortcode' parameter. This allows authenticated attackers, with administrator-level access to inject a PHP Object. If a POP chain is present via an additional pl...

CVSS:
7.2
Affected:
up to 2.6.3
Fixed in:
2.6.4
Disclosed:
Apr 9, 2024

CVE-2024-3020 on NVD →

Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sp_wp_carousel_shortcode'

medium

The Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the carousel widget in all versions up to, and including, 2.6.3 due to insufficient input saniti...

CVSS:
6.4
Affected:
up to 2.6.3
Fixed in:
2.6.4
Disclosed:
Apr 5, 2024

CVE-2024-2949 on NVD →

Carousel, Slider, Gallery by WP Carousel <= 2.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Carousel, Slider, Gallery by WP Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's shortcodes in versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping on supplied attributes. This makes it possible for authenticated attackers with contri...

CVSS:
6.4
Affected:
up to 2.5.2
Fixed in:
2.5.3
Disclosed:
Dec 22, 2022

CVE-2022-4482 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database