Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18724 | The Custom Post Carousels with Owl WordPress plugin before 1.4.12 uses the featherlight library and makes use of the data-featherlight attribute without sanitizing before using it. |
Fri, 11 Jul 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Howardehrenberg
Howardehrenberg custom Post Carousels With Owl |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:howardehrenberg:custom_post_carousels_with_owl:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Howardehrenberg
Howardehrenberg custom Post Carousels With Owl |
Mon, 23 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 20 Jun 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Custom Post Carousels with Owl WordPress plugin before 1.4.12 uses the featherlight library and makes use of the data-featherlight attribute without sanitizing before using it. | |
| Title | Custom Post Carousels with Owl < 1.4.12 - Contributor+ Stored XSS | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-06-23T20:22:09.795Z
Reserved: 2025-05-23T18:04:02.894Z
Link: CVE-2025-5125
Updated: 2025-06-23T20:22:04.311Z
Status : Analyzed
Published: 2025-06-20T06:15:21.993
Modified: 2025-07-11T14:32:42.780
Link: CVE-2025-5125
No data.
OpenCVE Enrichment
No data.
EUVD