CyberRota Analysis
AI-GeneratedThe vulnerability affects the Elementor Image Carousel plugin versions 1.1.1 and earlier, allowing for Cross-Site Scripting (XSS) attacks through custom links. This could enable attackers to inject malicious scripts, potentially compromising user data and site integrity. Website administrators using affected versions should prioritize patching to mitigate the risk of exploitation.
CVE
CVE-2026-65534
Severity
MEDIUM
CVSS
5.9
EPSS
0.15%
Original NVD Description
Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions.