Description
The Horizontal scrolling announcements WordPress plugin through 2.6 does not sanitise and escape one of its announcement settings before outputting it into an attribute context on the front end, allowing users granted access to the announcement management page (Contributor and above, once permitted) to perform Stored Cross-Site Scripting attacks that execute in the browser of anyone viewing the announcement.
Published: 2026-10-04
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 04 Oct 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions horizontal Scrolling Announcements
Vendors & Products Wordpress-extensions
Wordpress-extensions horizontal Scrolling Announcements

Sun, 04 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sun, 04 Oct 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Horizontal scrolling announcements WordPress plugin through 2.6 does not sanitise and escape one of its announcement settings before outputting it into an attribute context on the front end, allowing users granted access to the announcement management page (Contributor and above, once permitted) to perform Stored Cross-Site Scripting attacks that execute in the browser of anyone viewing the announcement.
Title Horizontal Scrolling Announcements <= 2.6 - Contributor+ Stored XSS via Style Field
References

Subscriptions

Wordpress-extensions Horizontal Scrolling Announcements
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-05T10:53:49.678Z

Reserved: 2026-07-24T09:48:24.498Z

Link: CVE-2026-17005

cve-icon Vulnrichment

Updated: 2026-10-05T10:50:42.796Z

cve-icon NVD

Status : Received

Published: 2026-10-04T07:16:33.907

Modified: 2026-10-05T11:16:48.327

Link: CVE-2026-17005

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T13:00:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')