medium · CVSS v3 5.4 · EPSS 0.00152
CVE-2026-17005
The Horizontal scrolling announcements WordPress plugin up to version 2.6 contains a stored XSS vulnerability that allows privileged users t
Overview
The Horizontal scrolling announcements WordPress plugin up to version 2.6 contains a stored XSS vulnerability that allows privileged users to inject malicious scripts into announcement attributes. This flaw can be exploited by contributors or higher roles to execute code in the browsers of any site visitor who views the affected announcement. The vulnerability is medium severity with a low EPSS score, indicating limited but still relevant risk.
Description
The Horizontal scrolling announcements WordPress plugin through 2.6 does not sanitise and escape one of its announcement settings before outputting it into an attribute context on the front end, allowing users granted access to the announcement management page (Contributor and above, once permitted) to perform Stored Cross-Site Scripting attacks that execute in the browser of anyone viewing the announcement.
Impact
Confidentiality is not directly compromised. Integrity can be affected as malicious scripts alter page content. Availability is not impacted. Site administrators and visitors viewing announcements are at risk of XSS execution.
Remediation
Apply the latest plugin update (v2.7 or later) which sanitises announcement inputs. If an update is unavailable, disable the plugin or restrict Contributor and higher roles from accessing the announcement management page. Additionally, implement a site-wide CSP that blocks inline scripts.
Risk context
Medium severity with an EPSS of 0.00152 indicates a low probability of exploitation but still warrants prompt patching to prevent XSS attacks.
Affected products
- WordPress
- Horizontal scrolling announcements plugin
- WordPress plugin
Scores
- Severity
- medium
- CVSS v2
- 3.5
- CVSS v3
- 5.4
- CVSS v4
- —
- EPSS
- 0.00152