Vulnerabilities > Shapedplugin > WP Carousel
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-04-06 | CVE-2024-2949 | Cross-site Scripting vulnerability in Shapedplugin WP Carousel The Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the carousel widget in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |