First published: Thu Mar 27 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in teastudio.pl WP Posts Carousel allows Stored XSS. This issue affects WP Posts Carousel: from n/a through 1.3.7.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress WP Posts Carousel | <=1.3.7 |
Update the WordPress WP Posts Carousel plugin to the latest available version (at least 1.3.8).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30920 is a stored Cross-site Scripting (XSS) vulnerability classified as a high severity issue.
To fix CVE-2025-30920, update the WP Posts Carousel plugin to version 1.3.8 or later.
CVE-2025-30920 affects the WP Posts Carousel plugin versions up to and including 1.3.7.
CVE-2025-30920 is categorized as a Cross-site Scripting (XSS) vulnerability.
Yes, CVE-2025-30920 can allow attackers to execute scripts in the context of users, potentially leading to data compromise.