CVE-2026-17005
Horizontal Scrolling Announcements <= 2.6 - Contributor+ Stored XSS via Style Field
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Horizontal scrolling announcements WordPress plugin through 2.6 does not sanitise and escape one of its announcement settings before outputting it into an attribute context on the front end, allowing users granted access to the announcement management page (Contributor and above, once permitted) to perform Stored Cross-Site Scripting attacks that execute in the browser of anyone viewing the announcement.
| Vendor | unknown |
| Product | horizontal scrolling announcements |
| Published | Oct 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown horizontal scrolling announcements
Be the first to know when new unknown vulnerabilities affecting unknown horizontal scrolling announcements are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Horizontal scrolling announcements
0 โค 2.6
References
Credits
testoun WPScan