CVE-2025-31535: WordPress Simple Owl Carousel plugin <= 1.1.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PressTigers Simple Owl Carousel simple-owl-carousel allows DOM-Based XSS.This issue affects Simple Owl Carousel: from n/a through <= 1.1.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31535?
CVE-2025-31535 is classified as a critical severity vulnerability due to its potential for exploitation via DOM-Based XSS attacks.
How do I fix CVE-2025-31535?
To fix CVE-2025-31535, update the PressTigers Simple Owl Carousel plugin to version 1.1.2 or later.
What applications are affected by CVE-2025-31535?
CVE-2025-31535 affects the Simple Owl Carousel plugin in versions up to and including 1.1.1.
What type of vulnerability is CVE-2025-31535?
CVE-2025-31535 is a Cross-site Scripting (XSS) vulnerability resulting from improper input neutralization.
What can an attacker do with CVE-2025-31535?
An attacker can exploit CVE-2025-31535 to execute arbitrary scripts in the context of the user's browser.