← WordPress Vulnerabilities
WordPress security by component

Responsive Posts Carousel Pro

Responsive Posts Carousel Pro is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Mar 05, 2026; the highest CVE/CNA score is 7.5.

Plugin slug: responsive-posts-carousel-pro

CVE-2026-27361: Responsive Posts Carousel Pro: A security weakness

Responsive Posts Carousel Pro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedMar 05, 2026
Safe version guidanceSee mitigation notes
Safe version
Mar 05, 2026 CVE-2026-27361
Responsive Posts Carousel Pro: A security weakness
Responsive Posts Carousel Pro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending
Dec 30, 2025 CVE-2025-68996
Responsive Posts Carousel Pro: Filesystem traversal
Responsive Posts Carousel Pro is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVDPending
Dec 23, 2025 CVE-2025-68548
Responsive Posts Carousel Pro: Cross-site scripting
Responsive Posts Carousel Pro is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Aug 14, 2025 CVE-2025-52728
Responsive Posts Carousel Pro: Filesystem traversal
Responsive Posts Carousel Pro is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVDPending