Cross-site Scripting Vulnerability in wpWax Product Carousel Slider for WooCommerce
CVE-2025-24681
5.9MEDIUM
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 24 January 2025
Summary
A Cross-site Scripting (XSS) vulnerability exists in the wpWax Product Carousel Slider & Grid Ultimate for WooCommerce, impacting versions from n/a through 1.10.0. This flaw allows for stored XSS, where an attacker can inject malicious scripts into web pages viewed by users. Users interacting with a vulnerable version may unintentionally execute harmful scripts, potentially leading to unauthorized access to sensitive data or other malicious actions. Regular updates and security monitoring are essential to safeguard against this type of vulnerability.
Affected Version(s)
Product Carousel Slider & Grid Ultimate for WooCommerce <= 1.10.0
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Damanpreet Singh (Patchstack Alliance)