Horizontal Scrolling Announcements <= 2.6 - Contributor+ Stored XSS via Style Field
Summary
| CVE | CVE-2026-17005 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-04 07:16:33 UTC |
| Updated | 2026-10-04 07:16:33 UTC |
| Description | The Horizontal scrolling announcements WordPress plugin through 2.6 does not sanitise and escape one of its announcement settings before outputting it into an attribute context on the front end, allowing users granted access to the announcement management page (Contributor and above, once permitted) to perform Stored Cross-Site Scripting attacks that execute in the browser of anyone viewing the announcement. |
Risk And Classification
Problem Types: CWE-79 Cross-Site Scripting (XSS)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Unknown | Horizontal Scrolling Announcements | affected 2.6 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/e3973475-18c4-46a0-b0ca-24e4d2cd58ca | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: testoun (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.