
Cloud Vulnerability DB
A community-led vulnerabilities database
The WP Posts Carousel plugin for WordPress contains a security vulnerability (CVE-2025-1491) discovered by researcher Krzysztof Zając. The vulnerability affects versions up to and including 1.3.7 of the plugin. This issue was identified and disclosed on March 1, 2025 (Wordfence Intel).
The vulnerability has been identified in the WP Posts Carousel plugin, with a CVSS score indicating moderate severity. The issue affects the plugin's authentication mechanisms, though specific technical details about the vulnerability type and attack vectors have not been publicly disclosed (NVD).
The vulnerability has been patched in version 1.3.8 of the WP Posts Carousel plugin. Users are advised to update to this latest version to address the security issues. The fix was implemented thanks to the collaborative efforts of Wordfence and researcher Krzysztof Zając (WordPress Plugin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."