Stored Cross-site Scripting Vulnerability in WP Posts Carousel by WordPress
CVE-2025-31094
6.5MEDIUM
What is CVE-2025-31094?
The WP Posts Carousel plugin for WordPress has a Cross-site Scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages. This flaw affects versions from n/a to 1.3.8, enabling stored XSS attacks when users view manipulated posts. Proper input sanitization is essential to mitigate this risk and protect users from potential data exposure.
Affected Version(s)
WP Posts Carousel <= 1.3.8