WP Posts Carousel
WP Posts Carousel has 5 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; all 5 are fixed as of September 2026. Their average CVSS score is 6.9, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2025 was the busiest year with 5 disclosures.
The most common weakness is Cross-Site Scripting, behind 4 of the records (80%). Other recurring categories include Deserialization Of Untrusted Data.
Every one of the 5 issues recorded for WP Posts Carousel has a vendor fix available, so running the current release closes all known holes.
4 independent researchers contributed these findings, most of them (2) reported by astra.r3verii. WP Posts Carousel is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2025-39358WP Posts Carousel <= 1.3.12 - Authenticated (Contributor+) PHP Object Injection
Read the full analysisVulnerability Records

WP Posts Carousel
Author
teastudio.pl
This plugin is under development, and we apologize for the lack of updates. The development is ongoing, and we are planning to release it in May 2025! 🚀 Stay tuned! WP Posts Carousel allows to view the list of selected post types in a carousel. The plugin offers rich parameters of carousel display and post information, and provides better support for mobile devices. The plugin is equipped with a code generator (allows to insert the carousel into content) and a dedicated widget. This plugin uses OWL Carousel in new version 2.0.0-beta.2.4. This plugin may require some others plugins or libraries: Font Awesome – this library is included but you can disable it on the plugin’s settings page WordPress Popular Posts – this plugin is required only if you want to display popular posts in the carousel Now available in the following Languages English (en_EN) Polish (pl_PL) If you need other translation or you would like to create some, please visit crowdin.com project page. For more information, check out PLUGIN HOMEPAGE. I will be grateful for opinions and reviews. Translations: English – by Marcin Gierada Polish – by Marcin Gierada
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C