WP Carousel Free <= 2.7.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-caption' Attribute
medium
The WP Carousel Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted fancybox `data-caption` attributes in all versions up to, and including, 2.7.10. This is due to the `fancybox-config.js` script reading the carousel container's `id` attribute directly from the DOM to construct a jQuery s...
- CVSS:
- 6.4
- Affected:
- up to 2.7.10
- Fixed in:
- 2.7.11
- Disclosed:
- May 4, 2026
CVE-2026-4665 on NVD →
Carousel, Slider, Gallery by WP Carousel <= 2.7.3 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Carousel, Slider, Gallery by WP Carousel – Image Carousel with Lightbox & Photo Gallery, Video Slider, Post Carousel & Post Grid, Product Carousel & Product Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 2.7.3 due to insufficient input sanit...
- CVSS:
- 4.4
- Affected:
- up to 2.7.3
- Fixed in:
- 2.7.4
- Disclosed:
- Jan 31, 2025
CVE-2024-13314 on NVD →
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library
medium
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...
- CVSS:
- 6.4
- Affected:
- up to 2.6.8
- Fixed in:
- 2.6.9
- Disclosed:
- Dec 3, 2024
CVE-2024-5020 on NVD →
Carousel, Slider, Gallery by WP Carousel <= 2.6.8 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The Carousel, Slider, Gallery by WP Carousel – Image Carousel with Lightbox & Photo Gallery, Video Slider, Post Carousel & Post Grid, Product Carousel & Product Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 2.6.8 due to insufficient input sanit...
- CVSS:
- 4.4
- Affected:
- up to 2.6.8
- Fixed in:
- 2.6.9
- Disclosed:
- Oct 30, 2024
CVE-2024-4002 on NVD →
Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 - Authenticated (Admin+) PHP Object Injection
high
The plugin is vulnerable to PHP Object Injection in versions up to and including, 2.6.3 via deserialization of untrusted input in the import function via the 'shortcode' parameter. This allows authenticated attackers, with administrator-level access to inject a PHP Object. If a POP chain is present via an additional pl...
- CVSS:
- 7.2
- Affected:
- up to 2.6.3
- Fixed in:
- 2.6.4
- Disclosed:
- Apr 9, 2024
CVE-2024-3020 on NVD →
Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sp_wp_carousel_shortcode'
medium
The Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the carousel widget in all versions up to, and including, 2.6.3 due to insufficient input saniti...
- CVSS:
- 6.4
- Affected:
- up to 2.6.3
- Fixed in:
- 2.6.4
- Disclosed:
- Apr 5, 2024
CVE-2024-2949 on NVD →
Carousel, Slider, Gallery by WP Carousel <= 2.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Carousel, Slider, Gallery by WP Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's shortcodes in versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping on supplied attributes. This makes it possible for authenticated attackers with contri...
- CVSS:
- 6.4
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.3
- Disclosed:
- Dec 22, 2022
CVE-2022-4482 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database