Description
Cross-Site Request Forgery (CSRF) vulnerability in alexvtn WIP WooCarousel Lite wip-woocarousel-lite allows Stored XSS.This issue affects WIP WooCarousel Lite: from n/a through <= 1.1.7.
Published: 2025-03-27
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery that enables a stored cross‑site scripting payload to be injected into the site through the WIP WooCarousel Lite plugin. Once stored, the malicious code will execute for every visitor to the website, potentially compromising session data, defacing content, or exfiltrating sensitive information. The weakness is classified as a stored XSS triggered by a CSRF flaw (CWE‑352).

Affected Systems

WordPress sites that have installed the WIP WooCarousel Lite plugin from its earliest release through version 1.1.7 are affected. Any site using a plugin version 1.1.7 or earlier may be vulnerable. The plugin is distributed by the user alexvtn.

Risk and Exploitability

The CVSS score of 7.1 reflects moderate to high severity, while the EPSS score of less than 1% indicates a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack requires the ability to submit a crafted HTTP request to the site; it is likely that the request must be made in the context of a logged‑in user with content‑creation privileges, but this is inferred from typical CSRF patterns, as the CVE description does not explicitly state the required authentication level. An attacker could force such a user to click a malicious link or open a crafted page that sends the request, thereby inserting the stored XSS payload.

Generated by OpenCVE AI on May 1, 2026 at 13:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update WIP WooCarousel Lite to version 1.1.8 or later, which removes the CSRF and XSS flaw.
  • If an update is not immediately available, disable or remove the plugin’s content‑creation endpoints until a patch can be applied to prevent CSRF requests from being accepted.
  • Review existing content created with the vulnerable plugin for injected JavaScript and cleanse or delete any malicious scripts before restoring the plugin functionality.

Generated by OpenCVE AI on May 1, 2026 at 13:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8396 Cross-Site Request Forgery (CSRF) vulnerability in alexvtn WIP WooCarousel Lite allows Stored XSS. This issue affects WIP WooCarousel Lite: from n/a through 1.1.7.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in alexvtn WIP WooCarousel Lite allows Stored XSS. This issue affects WIP WooCarousel Lite: from n/a through 1.1.7. Cross-Site Request Forgery (CSRF) vulnerability in alexvtn WIP WooCarousel Lite wip-woocarousel-lite allows Stored XSS.This issue affects WIP WooCarousel Lite: from n/a through <= 1.1.7.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 27 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Mar 2025 11:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in alexvtn WIP WooCarousel Lite allows Stored XSS. This issue affects WIP WooCarousel Lite: from n/a through 1.1.7.
Title WordPress WIP WooCarousel Lite plugin <= 1.1.7 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:56.858Z

Reserved: 2025-03-26T09:19:49.549Z

Link: CVE-2025-30769

cve-icon Vulnrichment

Updated: 2025-03-27T13:59:52.416Z

cve-icon NVD

Status : Deferred

Published: 2025-03-27T11:15:37.970

Modified: 2026-04-23T15:27:02.090

Link: CVE-2025-30769

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T13:15:20Z

Weaknesses