Executive brief
The Custom links in Elementor Image Carousel plugin for WordPress, which allows users to add unique URLs to images within carousels, is vulnerable to a security flaw. An attacker with 'Author' level permissions can inject malicious scripts into the website. If a site visitor or administrator views the affected content, the script could execute, potentially leading to unauthorized redirects, advertisement injection, or theft of session information.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the 'Custom links in Elementor Image Carousel' plugin for WordPress (versions <= 1.1.1). The flaw is rooted in improper neutralization of input during web page generation (CWE-79) within the custom link fields. An attacker with high-level privileges (Author or higher) can inject malicious JavaScript payloads into these fields. The script executes in the context of a victim's browser when they interact with or view the affected carousel. As of the advisory date, no official patch has been released.
Affected products
- Charlie Etienne Custom links in Elementor Image Carousel <= 1.1.1
Timeline
- 2026-06-12: other: Vulnerability reported by researcher Ananda Dhakal
- 2026-07-23: disclosed: Vulnerability published by Patchstack and NVD