PT-2025-45090 · WordPress · Carousel Block – Responsive Image/Content Carousel

Published

2025-11-05

·

Updated

2025-11-05

·

CVE-2025-12388

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions B Carousel Block – Responsive Image and Content Carousel versions up to and including 1.1.5
Description The B Carousel Block – Responsive Image and Content Carousel plugin for WordPress is susceptible to Server-Side Request Forgery. The issue stems from a lack of validation of user-supplied URLs before they are used in the wp remote request() function. This allows authenticated attackers with subscriber-level access or higher to make web requests to arbitrary locations from the web application, potentially enabling them to query and modify information from internal services.
Recommendations Update B Carousel Block – Responsive Image and Content Carousel to a version newer than 1.1.5.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-12388

Affected Products

Carousel Block – Responsive Image/Content Carousel