Junglewise Threat Intelligence

CVE-2026-65534: Charlie Etienne Custom links in Elementor Image Carousel XSS

CVE-2026-65534 · Severity: medium · CVSS 5.9 · Published 2026-07-23

Executive brief

The Custom links in Elementor Image Carousel plugin for WordPress, which allows users to add unique URLs to images within carousels, is vulnerable to a security flaw. An attacker with 'Author' level permissions can inject malicious scripts into the website. If a site visitor or administrator views the affected content, the script could execute, potentially leading to unauthorized redirects, advertisement injection, or theft of session information.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the 'Custom links in Elementor Image Carousel' plugin for WordPress (versions <= 1.1.1). The flaw is rooted in improper neutralization of input during web page generation (CWE-79) within the custom link fields. An attacker with high-level privileges (Author or higher) can inject malicious JavaScript payloads into these fields. The script executes in the context of a victim's browser when they interact with or view the affected carousel. As of the advisory date, no official patch has been released.

Affected products

  • Charlie Etienne Custom links in Elementor Image Carousel <= 1.1.1

Timeline

  • 2026-06-12: other: Vulnerability reported by researcher Ananda Dhakal
  • 2026-07-23: disclosed: Vulnerability published by Patchstack and NVD

References