The Horizontal scrolling announcements WordPress plugin through 2.6 does not sanitise and escape one of its announcement settings before outputting it into an attribute context on the front end, allowing users granted access to the announcement management page (Contributor and above, once permitted) to perform Stored Cross-Site Scripting attacks that execute in the browser of anyone viewing the announcement.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 04 Oct 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Sun, 04 Oct 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Horizontal scrolling announcements WordPress plugin through 2.6 does not sanitise and escape one of its announcement settings before outputting it into an attribute context on the front end, allowing users granted access to the announcement management page (Contributor and above, once permitted) to perform Stored Cross-Site Scripting attacks that execute in the browser of anyone viewing the announcement. | |
| Title | Horizontal Scrolling Announcements <= 2.6 - Contributor+ Stored XSS via Style Field | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-04T06:00:22.933Z
Reserved: 2026-07-24T09:48:24.498Z
Link: CVE-2026-17005
No data.
Status : Received
Published: 2026-10-04T07:16:33.907
Modified: 2026-10-04T07:16:33.907
Link: CVE-2026-17005
No data.
OpenCVE Enrichment
Updated: 2026-10-04T07:30:09Z
Weaknesses