CVE-2026-22347

WordPress Carousel Horizontal Posts Content Slider plugin <= 3.3.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in subhansanjaya Carousel Horizontal Posts Content Slider carousel-horizontal-posts-content-slider allows DOM-Based XSS.This issue affects Carousel Horizontal Posts Content Slider: from n/a through <= 3.3.2.


We have discovered 615 live websites that are affected by CVE-2026-22347.

Run a Free Instant Scan




Affected Software

Product  Carousel Horizontal Posts Content Slider
Category Wordpress Plugins
Vulnerable Domains615 live websites (100% of Carousel Horizontal Posts Content Slider install base)
Vulnerable Versions
  • from 0 through 3.3.2
Vulnerable Versions Count2 versions ( 100% of all versions)



Details

  • Published - Jan 22, 2026
  • Updated - Jan 27, 2026

Credits

  • Muhammad Yudha - DJ | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-22347
United States131 websites



Germany49 websites
Japan49 websites
Russia35 websites
Italy30 websites
France29 websites
Netherlands25 websites
Philippines23 websites
Spain21 websites
India20 websites

Website Distribution by TLD

Number of websites using CVE-2026-22347
.com219 websites
.org43 websites
.ru33 websites
.it28 websites
.de26 websites
.nl21 websites
.com.br15 websites
.net14 websites
.fr12 websites
.jp11 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-22347

Top websites that are affected by CVE-2026-22347. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.ru Russia**,***
**************.eu Czech Republic***,***
*****************.com Germany***,***
**********.com Japan***,***
***************.com United States***,***
*************.de Germany***,***
**************.org United States***,***
********************.org United States***,***
**********.com United States***,***
******.****.ua Ukraine***,***
See full domain list

FAQ

A total of 615 websites have been identified as vulnerable to CVE-2026-22347, based on global website indexing conducted by WebTechSurvey.
The Carousel Horizontal Posts Content Slider is affected by the CVE-2026-22347 vulnerability.
Carousel Horizontal Posts Content Slider versions up to and including 3.3.2 are vulnerable to CVE-2026-22347.