SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-65534

MEDIUM · CVSS 5.9 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The vulnerability affects the Elementor Image Carousel plugin versions 1.1.1 and earlier, allowing for Cross-Site Scripting (XSS) attacks through custom links. This could enable attackers to inject malicious scripts, potentially compromising user data and site integrity. Website administrators using affected versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-65534
Severity
MEDIUM
CVSS
5.9
EPSS
0.15%

Original NVD Description

Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions.