Impact
This vulnerability is a cross‑site scripting flaw in the Custom links in Elementor Image Carousel plugin, affecting all versions up to 1.1.1. When an attacker supplies a specially crafted link value, the plugin fails to escape or validate the input, allowing arbitrary JavaScript to execute in the context of a visitor’s browser. The flaw is classified as CWE‑79.
Affected Systems
The affected product is the WordPress plugin "Custom links in Elementor Image Carousel" developed by Charlie Etienne. All releases up to and including version 1.1.1 are vulnerable. Site owners using these plugin versions are at risk; newer releases are presumed to contain a fix.
Risk and Exploitability
The CVSS base score of 5.9 indicates moderate severity, and the EPSS score of < 1% suggests a low likelihood of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote via the web interface: an attacker must supply a malicious link value that is rendered by the plugin, typically through a post, page, or widget that includes the custom link feature. If the site publishes such links publicly, any visitor to the page could be impacted, making the exposure potentially widespread if not mitigated.
OpenCVE Enrichment