Cross-site Scripting Vulnerability in wpWax Product Carousel Slider for WooCommerce
CVE-2025-24681

5.9MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
24 January 2025

Summary

A Cross-site Scripting (XSS) vulnerability exists in the wpWax Product Carousel Slider & Grid Ultimate for WooCommerce, impacting versions from n/a through 1.10.0. This flaw allows for stored XSS, where an attacker can inject malicious scripts into web pages viewed by users. Users interacting with a vulnerable version may unintentionally execute harmful scripts, potentially leading to unauthorized access to sensitive data or other malicious actions. Regular updates and security monitoring are essential to safeguard against this type of vulnerability.

Affected Version(s)

Product Carousel Slider & Grid Ultimate for WooCommerce <= 1.10.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Damanpreet Singh (Patchstack Alliance)
.