Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jobair JB Horizontal Scroller News Ticker jb-horizontal-scroller-news-ticker allows DOM-Based XSS.This issue affects JB Horizontal Scroller News Ticker: from n/a through <= 1.0.
Published: 2025-01-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The JB Horizontal Scroller News Ticker plugin for WordPress contains an improper neutralization of input during web page generation, enabling DOM‑based XSS. The flaw allows an attacker to inject malicious scripts that will execute in the browsers of users who view the affected pages. This can lead to credential theft, session hijacking, defacement or the delivery of further malware, thereby compromising the confidentiality, integrity and availability of user interactions with the site.

Affected Systems

The vulnerability affects the Jobair JB Horizontal Scroller News Ticker plugin on WordPress installations running any version of the plugin up through 1.0. No specific patch version is listed, but all installations of v1.0 or earlier are susceptible.

Risk and Exploitability

The moderate CVSS score of 6.5 reflects the potential impact of this client‑side attack. The EPSS score of less than 1% suggests a low probability of exploitation at present, and the vulnerability is not catalogued in the CISA KEV list. Exploitation requires an attacker to provide malicious input that is rendered unsanitized on the page, typically through a configuration setting or content field that the plugin displays. While there is no direct remote code execution, the ability to run arbitrary JavaScript in the victim’s browser makes the risk significant for sites that allow untrusted input via the plugin.

Generated by OpenCVE AI on May 1, 2026 at 20:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update or replace the JB Horizontal Scroller News Ticker plugin with a version that removes the XSS flaw (v1.1 or later if available).
  • If a fix is not immediately available, disable the plugin or remove the affected widgets from live pages.
  • Ensure that any user‑supplied content displayed by the plugin is properly escaped or sanitized according to OWASP XSS Prevention Cheat Sheet guidelines.

Generated by OpenCVE AI on May 1, 2026 at 20:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3459 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jobair JB Horizontal Scroller News Ticker allows DOM-Based XSS.This issue affects JB Horizontal Scroller News Ticker: from n/a through 1.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jobair JB Horizontal Scroller News Ticker allows DOM-Based XSS.This issue affects JB Horizontal Scroller News Ticker: from n/a through 1.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jobair JB Horizontal Scroller News Ticker jb-horizontal-scroller-news-ticker allows DOM-Based XSS.This issue affects JB Horizontal Scroller News Ticker: from n/a through <= 1.0.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Fri, 17 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jobair JB Horizontal Scroller News Ticker allows DOM-Based XSS.This issue affects JB Horizontal Scroller News Ticker: from n/a through 1.0.
Title WordPress JB Horizontal Scroller News Ticker plugin <= 1.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-11T22:56:38.234Z

Reserved: 2025-01-16T11:30:51.097Z

Link: CVE-2025-23830

cve-icon Vulnrichment

Updated: 2025-01-17T17:17:56.360Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T21:15:24.213

Modified: 2026-06-17T08:57:34.960

Link: CVE-2025-23830

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T20:45:25Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')