Cross-site Scripting Vulnerability in wpWax Product Carousel Slider for WooCommerce
CVE-2025-24681
5.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 January 2025
What is CVE-2025-24681?
A Cross-site Scripting (XSS) vulnerability exists in the wpWax Product Carousel Slider & Grid Ultimate for WooCommerce, impacting versions from n/a through 1.10.0. This flaw allows for stored XSS, where an attacker can inject malicious scripts into web pages viewed by users. Users interacting with a vulnerable version may unintentionally execute harmful scripts, potentially leading to unauthorized access to sensitive data or other malicious actions. Regular updates and security monitoring are essential to safeguard against this type of vulnerability.
Affected Version(s)
Product Carousel Slider & Grid Ultimate for WooCommerce <= 1.10.0