First published: Fri Jan 24 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpWax Product Carousel Slider & Grid Ultimate for WooCommerce allows Stored XSS. This issue affects Product Carousel Slider & Grid Ultimate for WooCommerce: from n/a through 1.10.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
wpWax Product Carousel Slider & Grid Ultimate for WooCommerce | <=1.10.0 |
Update the WordPress Product Carousel Slider & Grid Ultimate for WooCommerce wordpress plugin to the latest available version (at least 1.10.1).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24681 has a high severity due to its potential to allow stored cross-site scripting (XSS) attacks.
To fix CVE-2025-24681, update the wpWax Product Carousel Slider & Grid Ultimate for WooCommerce to the latest version beyond 1.10.0.
The consequences of CVE-2025-24681 include the ability for an attacker to inject malicious scripts that can compromise user data and take over user sessions.
CVE-2025-24681 affects the wpWax Product Carousel Slider & Grid Ultimate for WooCommerce from versions n/a through 1.10.0.
As of now, there are no publicly reported exploits for CVE-2025-24681, but it is advisable to secure your site against potential attacks.