Medium severity5.4NVD Advisory· Published Mar 27, 2023· Updated Jun 17, 2026
CVE-2023-0589
CVE-2023-0589
Description
The WP Image Carousel WordPress plugin through 1.0.2 does not sanitise and escape some parameters, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:wp_image_carousel_project:wp_image_carousel:*:*:*:*:*:wordpress:*:*Range: <=1.0.2
- Range: <=1.0.2
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/58649228-69a6-4028-8487-166b0a07fcf7nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.