WP Clinic
Log in Sign up

PLUGIN SECURITY

Is Wow Carousel For Divi Lite safe?

Create beautiful, responsive image and logo carousels for the Divi Builder — no code required.

What this plugin does

  • Slug: wow-carousel-for-divi-lite
  • Author: Fahim Reza
  • 30000+ active installs
  • 96/100 rating (146 reviews on wordpress.org)
  • 622611 all-time downloads
  • On WordPress.org since 2020-06-28

carouseldividivi carouselImage carousellogo carousel

Maintenance status

  • Last updated: 2026-03-12 9:48pm GMT
  • Tested up to WordPress: 6.9.5
  • Requires PHP: 7.4+

Known vulnerabilities

2 known CVEs on file for Wow Carousel For Divi Lite.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-33999 Divi Carousel Free (Divi5 Support) [wow-carousel-for-divi-lite] < 1.2.12 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 1.2.12 1.2.12 2023-07-18
CVE-2025-0350 Divi Carousel Free (Divi5 Support) [wow-carousel-for-divi-lite] < 2.1.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.1.0 2.1.0 0000-00-00

CVE-2023-33999

Update the WordPress Divi Carousel Lite plugin to the latest available version. Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Divi Carousel Lite Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.2.12.

Source: Patchstack

CVE-2025-0350

The Divi Carousel Maker – Image, Logo, Testimonial, Post Carousel & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Carousel and Logo Carousel in all versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.