A vulnerability marked as problematic has been reported in GhozyLab Image Carousel Plugin up to 1.0.0.41 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.

This vulnerability is traded as CVE-2025-68074. It is possible to initiate the attack remotely. There is no exploit available.