rootpwn

medium · CVSS v3 5.4 · EPSS 0.00152

CVE-2026-17005

The Horizontal scrolling announcements WordPress plugin up to version 2.6 contains a stored XSS vulnerability that allows privileged users t

Overview

The Horizontal scrolling announcements WordPress plugin up to version 2.6 contains a stored XSS vulnerability that allows privileged users to inject malicious scripts into announcement attributes. This flaw can be exploited by contributors or higher roles to execute code in the browsers of any site visitor who views the affected announcement. The vulnerability is medium severity with a low EPSS score, indicating limited but still relevant risk.

Description

The Horizontal scrolling announcements WordPress plugin through 2.6 does not sanitise and escape one of its announcement settings before outputting it into an attribute context on the front end, allowing users granted access to the announcement management page (Contributor and above, once permitted) to perform Stored Cross-Site Scripting attacks that execute in the browser of anyone viewing the announcement.

Impact

Confidentiality is not directly compromised. Integrity can be affected as malicious scripts alter page content. Availability is not impacted. Site administrators and visitors viewing announcements are at risk of XSS execution.

Remediation

Apply the latest plugin update (v2.7 or later) which sanitises announcement inputs. If an update is unavailable, disable the plugin or restrict Contributor and higher roles from accessing the announcement management page. Additionally, implement a site-wide CSP that blocks inline scripts.

Risk context

Medium severity with an EPSS of 0.00152 indicates a low probability of exploitation but still warrants prompt patching to prevent XSS attacks.

Affected products

  • WordPress
  • Horizontal scrolling announcements plugin
  • WordPress plugin

Scores

Severity
medium
CVSS v2
3.5
CVSS v3
5.4
CVSS v4
—
EPSS
0.00152

XSS WordPress Stored XSS Plugin Contributor Medium EPSS

← All CVEs