Description
The Horizontal scrolling announcements WordPress plugin through 2.6 does not sanitise and escape one of its announcement settings before outputting it into an attribute context on the front end, allowing users granted access to the announcement management page (Contributor and above, once permitted) to perform Stored Cross-Site Scripting attacks that execute in the browser of anyone viewing the announcement.
Published: 2026-10-04
Score: n/a
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting (XSS)
Action: Immediate Patch
AI Analysis

Impact

The 2.6 release of the Horizontal scrolling announcements WordPress plugin fails to sanitize a style field that is echoed into an attribute on the front end, permitting users with Contributor or higher access to inject arbitrary JavaScript. The stored payload is then delivered to any visitor who views the announcement, enabling classic XSS effects such as cookie theft, session hijacking or execution of arbitrary client‑side code. The flaw is a classic stored input‑validation weakness represented by CWE‑79 and does not involve privilege escalation beyond the user’s existing role. The impact is confined to browsers that load the vulnerable announcement, potentially exposing sensitive data or enabling further client‑side attacks.

Affected Systems

The vulnerability affects all WordPress sites running the Horizontal scrolling announcements plugin version 2.6 or earlier. Any site that has tuned the plugin’s settings to allow Contributors or other roles to edit announcements is susceptible. No other versions or software components are listed as affected.

Risk and Exploitability

The CVSS score is not published and the EPSS estimate is unavailable, which limits quantitative risk assessment. However, the flaw is a classic stored XSS that requires the attacker to have Contributor‑level or higher privileges, which limits the attack surface. Once the payload is stored, it automatically impacts all users who view the announcement; the attack vector is inferred to be an authenticated user creating the malicious data. The vulnerability is not indexed in the CISA KEV catalog, but its potential for widespread client‑side compromise warrants urgent attention.

Generated by OpenCVE AI on October 4, 2026 at 07:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a fixed version of the plugin if one is available
  • If an upgrade cannot be performed immediately, revoke the Contributor role’s ability to edit announcements or disable the plugin until a patch is released
  • Apply a strict Content Security Policy that blocks inline JavaScript execution to mitigate the risk of stored XSS

Generated by OpenCVE AI on October 4, 2026 at 07:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sun, 04 Oct 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Horizontal scrolling announcements WordPress plugin through 2.6 does not sanitise and escape one of its announcement settings before outputting it into an attribute context on the front end, allowing users granted access to the announcement management page (Contributor and above, once permitted) to perform Stored Cross-Site Scripting attacks that execute in the browser of anyone viewing the announcement.
Title Horizontal Scrolling Announcements <= 2.6 - Contributor+ Stored XSS via Style Field
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-04T06:00:22.933Z

Reserved: 2026-07-24T09:48:24.498Z

Link: CVE-2026-17005

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T07:16:33.907

Modified: 2026-10-04T07:16:33.907

Link: CVE-2026-17005

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T07:30:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')