PT-2025-38941 · Unknown · Themepoints Carousel Ultimate

Published

2025-09-22

·

Updated

2025-09-23

·

CVE-2025-58652

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Themepoints Carousel Ultimate versions through 1.8
Description The software contains a flaw related to improper input handling during web page creation, which allows for Stored Cross-site Scripting (XSS). This issue enables malicious code injection through web pages. The affected component is susceptible to attacks where an attacker can inject malicious scripts into web pages viewed by other users.
Recommendations Update Themepoints Carousel Ultimate to a version later than 1.8.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-58652

Affected Products

Themepoints Carousel Ultimate