Impact
The 2.6 release of the Horizontal scrolling announcements WordPress plugin fails to sanitize a style field that is echoed into an attribute on the front end, permitting users with Contributor or higher access to inject arbitrary JavaScript. The stored payload is then delivered to any visitor who views the announcement, enabling classic XSS effects such as cookie theft, session hijacking or execution of arbitrary client‑side code. The flaw is a classic stored input‑validation weakness represented by CWE‑79 and does not involve privilege escalation beyond the user’s existing role. The impact is confined to browsers that load the vulnerable announcement, potentially exposing sensitive data or enabling further client‑side attacks.
Affected Systems
The vulnerability affects all WordPress sites running the Horizontal scrolling announcements plugin version 2.6 or earlier. Any site that has tuned the plugin’s settings to allow Contributors or other roles to edit announcements is susceptible. No other versions or software components are listed as affected.
Risk and Exploitability
The CVSS score is not published and the EPSS estimate is unavailable, which limits quantitative risk assessment. However, the flaw is a classic stored XSS that requires the attacker to have Contributor‑level or higher privileges, which limits the attack surface. Once the payload is stored, it automatically impacts all users who view the announcement; the attack vector is inferred to be an authenticated user creating the malicious data. The vulnerability is not indexed in the CISA KEV catalog, but its potential for widespread client‑side compromise warrants urgent attention.
OpenCVE Enrichment