Cross-site Scripting Vulnerability in Imran Emu Logo Slider and Related Products
CVE-2025-62121
5.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 31 December 2025
What is CVE-2025-62121?
A Cross-site Scripting (XSS) vulnerability exists in Imran Emu Logo Slider and its related products, allowing attackers to inject malicious scripts into web pages. This issue affects versions of Logo Slider, Logo Carousel, Logo Showcase, and Client Logo up to 1.8.1, enabling potential exploitation where stored user data can be showcased without proper sanitization. Attackers can manipulate input fields, leading to unauthorized access to sensitive information and potentially compromising user sessions.
Affected Version(s)
Logo Slider , Logo Carousel , Logo showcase , Client Logo <= 1.8.1
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nabil Irawan | Patchstack Bug Bounty Program