Description
Cross-Site Request Forgery (CSRF) vulnerability in Bhaskar Dhote Post Carousel Slider post-carousel-slider allows Stored XSS.This issue affects Post Carousel Slider: from n/a through <= 2.0.1.
Published: 2025-01-31
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A Cross‑Site Request Forgery vulnerability exists in the Bhaskar Dhote Post Carousel Slider plugin that allows an attacker to store malicious scripts within the site’s content. By exploiting the lack of CSRF protection on forms that submit carousel content, an attacker can cause arbitrary JavaScript to be stored and later executed in the browsers of any visitor who loads the affected carousel. This leads to potential theft of session cookies, credential compromise, or other malicious actions as the victim. The weakness is identified as CWE‑352, which denotes missing or ineffective CSRF defenses.

Affected Systems

The flaw affects all installations of the Post Carousel Slider plugin with a version through 2.0.1. The vendor listed is Bhaskar Dhote. No specific sub‑version ranges beyond <= 2.0.1 are provided, so all releases in that range are considered vulnerable.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.1, indicating a high impact potential. The EPSS score is reported as < 1%, suggesting a low probability of exploitation at present, but the lack of verification from CISA KEV does not diminish the risk. Based on the description, the likely attack vector is a web‑based CSRF attempt that triggers a harmless form submission which stores malicious payloads; an attacker can embed a link or image that forces the site to process the attacker's input under the victim's credentials. The high CVSS score combined with the ease of generating CSRF requests means that once the vulnerability is discovered, an attacker can potentially compromise many users before mitigation.

Generated by OpenCVE AI on May 2, 2026 at 05:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Post Carousel Slider to a version newer than 2.0.1 that removes the CSRF issue or replace the plugin entirely.
  • If an immediate upgrade is not possible, deactivate or uninstall the plugin to eliminate the attack surface.
  • If the carousel functionality must remain, sanitize or strip all user‑supplied content from the plugin before storing or rendering it, which prevents stored scripts from executing.

Generated by OpenCVE AI on May 2, 2026 at 05:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3578 Cross-Site Request Forgery (CSRF) vulnerability in Bhaskar Dhote Post Carousel Slider allows Stored XSS. This issue affects Post Carousel Slider: from n/a through 2.0.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Bhaskar Dhote Post Carousel Slider allows Stored XSS. This issue affects Post Carousel Slider: from n/a through 2.0.1. Cross-Site Request Forgery (CSRF) vulnerability in Bhaskar Dhote Post Carousel Slider post-carousel-slider allows Stored XSS.This issue affects Post Carousel Slider: from n/a through <= 2.0.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00019}

epss

{'score': 0.00023}


Fri, 31 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jan 2025 08:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Bhaskar Dhote Post Carousel Slider allows Stored XSS. This issue affects Post Carousel Slider: from n/a through 2.0.1.
Title WordPress Post Carousel Slider plugin <= 2.0.1 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:26.622Z

Reserved: 2025-01-16T11:33:14.050Z

Link: CVE-2025-23977

cve-icon Vulnrichment

Updated: 2025-01-31T19:28:45.944Z

cve-icon NVD

Status : Deferred

Published: 2025-01-31T09:15:08.687

Modified: 2026-06-17T08:57:49.627

Link: CVE-2025-23977

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T05:15:16Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)