PT-2025-26919 · WordPress · Owl Carousel

Peter Thaleikis

·

Published

2025-06-26

·

Updated

2025-07-01

·

CVE-2025-5590

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Owl carousel responsive plugin for WordPress versions up to, and including, 1.9
Description: The issue is related to time-based SQL Injection via the id parameter due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Recommendations: For versions up to, and including, 1.9, consider disabling the id parameter in the affected plugin until a patch is available. Restrict access to the plugin to minimize the risk of exploitation, ensuring only necessary users have Contributor-level access and above. Avoid using the id parameter in the affected plugin until the issue is resolved.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-5590

Affected Products

Owl Carousel