CVE-2025-3863
Published
CVSS v3
4.3
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT
Description
The Post Carousel Slider for Elementor plugin for WordPress is vulnerable to improper authorization due to a missing capability check on the process_wbelps_promo_form() function in all versions up to, and including, 1.6.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to trigger the plugin’s support‐form handler to send arbitrary emails to the site’s support address.
<p><strong>Post Carousel Slider for Elementor</strong> Lets you display your WordPress <strong>Posts as Carousel Slider</strong>. You can now show your posts using this plugin easily to your users as a <strong>Carousel Slider</strong>. It helps you to create beautiful <strong>Post carousels</strong> with Images, Post Title, Post Excerpt, Read More Button in a nice sliding manner.</p>
<blockquote>
<p><strong><a href="https://plugin-devs.com/product/post-carousel-slider-for-elementor/" rel="nofollow ugc">Upgrade to Pro!</a></strong></p>
</blockquote>
<h3>Features</h3>
<ul>
<li>Choose Between <strong>Posts and Pages</strong></li>
<li>Filter Posts with <strong>Categories, Tags, Formats</strong> and other <strong>Custom Taxonomies</strong> related to Blog Posts</li>
<li>Filter Posts and Pages with <strong>Post Status</strong></li>
<li><strong>Limit Posts</strong></li>
<li><strong>Show or Hide Image</strong></li>
<li>Choose <strong>Image Size</strong> from WordPress Registered <strong>Image Sizes</strong></li>
<li><strong>Custom Image Size</strong></li>
<li><strong>Multiple Slideshows</strong> (supports more than one carousel per view).</li>
<li>Choose <strong>Sliding Items Per View</strong></li>
<li>Choose <strong>Slide to Scroll</strong> Number</li>
<li>Customizable Color, Hover, and Background Option to match the slider look with your taste and feel</li>
<li>Option to change <strong>Read More Text</strong></li>
<li>Extremely <strong>User Friendly</strong> settings panel for coders and non-coders alike.</li>
<li>Unique Settings for every carousel.</li>
<li>Support all Modern Browsers: <strong>Firefox, Chrome, IE, Safari etc</strong>.</li>
<li>Unlimited Slider on One Page</li>
<li><strong>Custom CSS</strong></li>
<li><strong>Free Basic Support.</strong><br />
> <strong>More Features are Coming Soon</strong></li>
</ul>
<blockquote>
<p><strong><a href="https://plugin-devs.com/product/post-carousel-slider-for-elementor/" rel="nofollow ugc">Upgrade to Pro!</a></strong></p>
</blockquote>
<p>There is also a <a href="https://plugin-devs.com/product/post-carousel-slider-for-elementor/" rel="nofollow ugc">Pro Version</a> of this plugin. You will get more features and advantages on the <a href="https://plugin-devs.com/product/post-carousel-slider-for-elementor/" rel="nofollow ugc">Pro Version</a>. <strong><a href="https://plugin-devs.com/product/post-carousel-slider-for-elementor/" rel="nofollow ugc">Post Carousel Slider for Elementor Pro</a></strong> is a multi-purpose responsive <strong>Post Showcase plugin</strong> that allows you to show more <strong>Posts (any post type)</strong> in a beautiful <strong>Carousel Slider</strong>. It has plenty of extremely user-friendly options and supports <strong>Post, Custom Post, Taxonomy, Custom Taxonomy, Specific Posts, and more</strong>. You can fully <strong>Customize the Style</strong> with the <a href="https://plugin-devs.com/product/post-carousel-slider-for-elementor/" rel="nofollow ugc">PRO Version</a>.</p>
<blockquote>
<p><strong><a href="https://plugin-devs.com/product/post-carousel-slider-for-elementor/" rel="nofollow ugc">Upgrade to Pro!</a></strong></p>
</blockquote>
<h3>Pro Features</h3>
<ul>
<li>Elementor PRO <strong>Loop Builder support</strong> to create your <strong>Own Custom Template</strong></li>
<li>Choose Posts from <strong>Any Post Types (Including Custom Post Types, WooCommerce Products)</strong></li>
<li>Filter From Any <strong>Custom Taxonomies</strong> Related to the Chosen Post Type</li>
<li><strong>Include Specific Post</strong> by Search from Chosen Post Type</li>
<li><strong>Exclude Specific Post</strong> by Search from Chosen Post Type</li>
<li><strong>Ignore Sticky Posts</strong></li>
<li><strong>Order</strong> Posts in <strong>Ascending/Descending</strong> Order</li>
<li><strong>Order</strong> Posts by <strong>Publish Date, ID, Post Title, Post Name (Slug), Menu Order, Modified Date, Randomly, Number of Comments</strong></li>
<li><strong>Two Types of Templates</strong>. Adding More Continuously</li>
<li>Option to Add <strong>Multiple Rows</strong></li>
<li><strong>Responsive Breakpoint Builder with Slider Options</strong> to customize Slider on different Screen</li>
<li><strong>AutoPlay to Move the Slider Automatically</strong></li>
<li>Change <strong>AutoPlay Speed</strong></li>
<li>Change <strong>Slide Speed</strong></li>
<li><strong>Pause Slider</strong> on Mouse Hover</li>
<li><strong>Multiple Rows</strong></li>
<li><strong>Rows Per Views</strong></li>
<li><strong>Show or Hide Title</strong></li>
<li><strong>Show or Hide Excerpt</strong></li>
<li><strong>Show or Hide Read More Button</strong></li>
<li><strong>Show or Hide Dots</strong></li>
<li><strong>Show or Hide Navigation Arrows</strong></li>
<li>Option to <strong>Limit Words</strong></li>
<li>Option to <strong>Limit Characters</strong></li>
<li>Custom <strong>Arrow Icons</strong> from <strong>Font Awesome Icon</strong> and <strong>SVG Icon</strong></li>
<li><strong>Fully Customizable Style</strong></li>
<li>Choose <strong>Spacing Between Items</strong></li>
<li>All Free Features</li>
<li><strong>Custom JS</strong></li>
<li>Ability to create your <strong>Customizable Template</strong> using Elementor PRO Loop Builder</li>
<li><strong>Priority Support</strong></li>
</ul>
<blockquote>
<p><strong>More Features are Coming Soon</strong></p>
<p><strong><a href="https://plugin-devs.com/product/post-carousel-slider-for-elementor/" rel="nofollow ugc">Upgrade to Pro!</a></strong></p>
</blockquote>
<p>** We welcome your feedback and new feature requests to improve the plugin! Please contact with us at <a href="mailto:[email protected]" rel="nofollow ugc"><strong>[email protected]</strong></a> for new <strong>Feature Requests</strong>**</p>