PT-2025-40496 · WordPress · Ultimate Multi Design Video Carousel

Nabil Irawan

·

Published

2025-10-03

·

Updated

2025-10-03

·

CVE-2025-9372

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Ultimate Multi Design Video Carousel plugin for WordPress versions prior to 1.5
Description The software is susceptible to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping. This allows authenticated attackers with editor-level access to inject arbitrary web scripts into pages. These scripts will execute when a user accesses the affected page. This issue only impacts multi-site installations and those where unfiltered html has been disabled.
Recommendations Update The Ultimate Multi Design Video Carousel plugin to version 1.5 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-9372

Affected Products

Ultimate Multi Design Video Carousel