Impact
The Any News Ticker plugin contains a stored cross‑site scripting flaw that allows authenticated contributors or higher to inject arbitrary JavaScript into the plugin’s shortcode attributes. The injected script is stored in the database and is rendered whenever a visitor loads a page that includes the affected shortcode, potentially allowing an attacker to hijack user sessions, modify page content, or exfiltrate data. This vulnerability is a classic input validation and output escaping weakness identified as CWE‑79.
Affected Systems
The flaw exists in all releases of the mucasoft Any News Ticker WordPress plugin up to and including version 3.1.1. Sites running a vulnerable version of the plugin under a WordPress installation are at risk.
Risk and Exploitability
The CVSS score of 6.4 indicates a medium severity vulnerability. The EPSS score of less than 1% suggests that exploitation is rare, and the vulnerability is not listed in the CISA KEV catalog. Because the attack requires authenticated access at the contributor level or higher, an attacker must first obtain valid credentials on the WordPress site. Once authenticated, the attacker can submit malicious attribute values via the plugin’s shortcode, which are saved and later executed for any site visitor, making the exploitation straightforward for the legitimate user who first creates or edits the content.
OpenCVE Enrichment
EUVD