๐Ÿ” CVE Alert

CVE-2026-17005

UNKNOWN 0.0

Horizontal Scrolling Announcements <= 2.6 - Contributor+ Stored XSS via Style Field

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Horizontal scrolling announcements WordPress plugin through 2.6 does not sanitise and escape one of its announcement settings before outputting it into an attribute context on the front end, allowing users granted access to the announcement management page (Contributor and above, once permitted) to perform Stored Cross-Site Scripting attacks that execute in the browser of anyone viewing the announcement.

Vendor unknown
Product horizontal scrolling announcements
Published Oct 4, 2026
Stay Ahead of the Next One

Get instant alerts for unknown horizontal scrolling announcements

Be the first to know when new unknown vulnerabilities affecting unknown horizontal scrolling announcements are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Horizontal scrolling announcements
0 โ‰ค 2.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/e3973475-18c4-46a0-b0ca-24e4d2cd58ca/

Credits

testoun WPScan