Cross-site Scripting Vulnerability in wpWax Product Carousel Slider for WooCommerce
CVE-2025-24681
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 January 2025
What is CVE-2025-24681?
A Cross-site Scripting (XSS) vulnerability exists in the wpWax Product Carousel Slider & Grid Ultimate for WooCommerce, impacting versions from n/a through 1.10.0. This flaw allows for stored XSS, where an attacker can inject malicious scripts into web pages viewed by users. Users interacting with a vulnerable version may unintentionally execute harmful scripts, potentially leading to unauthorized access to sensitive data or other malicious actions. Regular updates and security monitoring are essential to safeguard against this type of vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Product Carousel Slider & Grid Ultimate for WooCommerce <= 1.10.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved