Executive brief
The Image Carousel plugin for WordPress, which is used to display rotating image galleries on websites, contains a security flaw that allows users with 'Contributor' level access to inject malicious scripts. If an administrator or another site visitor views the affected page, these scripts could execute in their browser, potentially leading to unauthorized actions, website defacement, or redirection to malicious sites. This vulnerability poses a risk to site integrity and visitor safety, particularly on sites where multiple users have content creation privileges.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in the GhozyLab Image Carousel plugin for WordPress (versions up to and including 1.0.0.41). The flaw is caused by improper neutralization of user-supplied input during web page generation (CWE-79). An attacker with 'Contributor' or higher privileges can inject malicious HTML or JavaScript payloads into the plugin's settings or content. These scripts are then executed in the context of a victim's browser (typically a site administrator) when they interact with the affected page. As of the advisory date, no official patch has been released.
Affected products
- GhozyLab (WordPress) Image Carousel <= 1.0.0.41
Timeline
- 2025-10-15: other: Reported by researcher Muhammad Yudha - DJ
- 2026-06-26: advisory: Published by Patchstack and NVD