Stored Cross-Site Scripting Vulnerability in Ultimate Multi Design Video Carousel for WordPress
CVE-2025-9372

5.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
3 October 2025

What is CVE-2025-9372?

The Ultimate Multi Design Video Carousel plugin for WordPress is prone to Stored Cross-Site Scripting (XSS) vulnerabilities due to inadequate input sanitization and output escaping processes. Attackers with editor-level access can exploit this flaw, allowing them to inject arbitrary web scripts into pages. These malicious scripts can execute whenever an unsuspecting user visits the affected pages. This vulnerability specifically impacts multi-site setups and installations with unfiltered_html disabled, highlighting the urgent need for updates to safeguard against potential exploits.

Affected Version(s)

Ultimate Multi Design Video Carousel * <= 1.4

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan
.
CVE-2025-9372 : Stored Cross-Site Scripting Vulnerability in Ultimate Multi Design Video Carousel for WordPress