
Carousel Horizontal Posts Content Slider Security & Risk Analysis
wordpress.org/plugins/carousel-horizontal-posts-content-sliderA simple posts content slider, product, images, videos, related posts, custom post type carousel plugin for WordPress.
Is Carousel Horizontal Posts Content Slider Safe to Use in 2026?
Mostly Safe
Score 78/100Carousel Horizontal Posts Content Slider is generally safe to use. 1 past CVE were resolved. Keep it updated.
The "carousel-horizontal-posts-content-slider" plugin v3.3.2 exhibits a mixed security posture. While it demonstrates good practices such as exclusively using prepared statements for SQL queries and performing capability checks on all identified entry points, significant concerns remain. The presence of two AJAX handlers without authentication checks presents a clear attack vector, potentially allowing unauthorized actions. Furthermore, the taint analysis revealed one flow with an unsanitized path, which, despite not being classified as critical or high severity, warrants attention due to the potential for unexpected behavior or vulnerabilities.
The plugin's vulnerability history, particularly the single known medium-severity CVE related to Cross-Site Scripting, is a notable weakness. The fact that this vulnerability is currently unpatched is a critical concern, as it exposes users to known risks. The timing of the last vulnerability being in late 2025 also suggests a potential lack of active maintenance or a future unpatched issue. Overall, while the plugin avoids some common pitfalls like raw SQL queries, the combination of unprotected AJAX handlers and an unpatched XSS vulnerability significantly elevates its risk profile.
Key Concerns
- Unpatched CVE (medium severity)
- AJAX handlers without authentication checks
- Flows with unsanitized paths
- Bundled outdated library (jQuery v1.8.2)
Carousel Horizontal Posts Content Slider Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Carousel Horizontal Posts Content Slider <= 3.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Carousel Horizontal Posts Content Slider Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Carousel Horizontal Posts Content Slider Attack Surface
AJAX Handlers 3
Shortcodes 1
WordPress Hooks 25
Maintenance & Trust
Carousel Horizontal Posts Content Slider Maintenance & Trust
Maintenance Signals
Community Trust
Carousel Horizontal Posts Content Slider Alternatives
Post Grid
post-grid
Post Grid is a powerful WordPress plugin for creating customizable post grid layouts with advanced query options, allowing users to display posts dyna …
Trending/Popular Post Slider and Widget
wp-trending-post-slider-and-widget
A quick, easy way to add Popular/Trending posts slider, grid block and widget. Also work with Gutenberg shortcode block.
JWD PostSlider Widget
jwd-postslider-widget
Display your posts through a full responsive and highly customisable carousel widget.
WP Posts Carousel
wp-posts-carousel
WP Posts Carousel is a widget and a shortcode generator to displays posts or custom post types in Owl Carousel.
Post Sliders
post-sliders
Post Slider Plugin is a handy and effective solution for anyone seeking a responsive post slider. It offers a variety of slider templates to set up yo …
Carousel Horizontal Posts Content Slider Developer Profile
3 plugins · 12K total installs
How We Detect Carousel Horizontal Posts Content Slider
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/carousel-horizontal-posts-content-slider/assets/js/owl.carousel.js/wp-content/plugins/carousel-horizontal-posts-content-slider/assets/css/owl.carousel.css/wp-content/plugins/carousel-horizontal-posts-content-slider/assets/css/owl.theme.css/wp-content/plugins/carousel-horizontal-posts-content-slider/assets/css/custom.css/wp-content/plugins/carousel-horizontal-posts-content-slider/assets/js/carousel-horizontal-posts-content-slider.js/wp-content/plugins/carousel-horizontal-posts-content-slider/assets/js/main.js/wp-content/plugins/carousel-horizontal-posts-content-slider/assets/js/owl.carousel.js/wp-content/plugins/carousel-horizontal-posts-content-slider/assets/js/carousel-horizontal-posts-content-slider.js/wp-content/plugins/carousel-horizontal-posts-content-slider/assets/js/main.js/wp-content/plugins/carousel-horizontal-posts-content-slider/assets/js/owl.carousel.js?ver=/wp-content/plugins/carousel-horizontal-posts-content-slider/assets/css/owl.carousel.css?ver=/wp-content/plugins/carousel-horizontal-posts-content-slider/assets/css/owl.theme.css?ver=/wp-content/plugins/carousel-horizontal-posts-content-slider/assets/css/custom.css?ver=/wp-content/plugins/carousel-horizontal-posts-content-slider/assets/js/carousel-horizontal-posts-content-slider.js?ver=/wp-content/plugins/carousel-horizontal-posts-content-slider/assets/js/main.js?ver=HTML / DOM Fingerprints
wa-chpcs-review-noticewa-chpcs-plugin-iconwa-chpcs-notice-textwa-chpcs-review-actionsrate-wp-carouselwa_chpcs_fieldwa_chpcs_actionwa_chpcs_field