The Carousel Slider WordPress plugin before 2.2.11 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks
CVE ID: CVE-2024-4372
Vendor: Unknown
Product: Carousel Slider
EPSS Score: 0.03% (probability of being exploited)
EPSS Percentile: 6.56% (scored less or equal to compared to others)
EPSS Date: 2025-04-25 (when was this score calculated)
SSVC Exploitation: none
SSVC Technical Impact: partial
SSVC Automatable: false