CVE WATCH / VULNERABILITY DETAIL

CVE-2026-17005

UNKNOWNCVSS 0NVD feed

Published 4 October 2026 · tracked since 4 October 2026

Description

The Horizontal scrolling announcements WordPress plugin through 2.6 does not sanitise and escape one of its announcement settings before outputting it into an attribute context on the front end, allowing users granted access to the announcement management page (Contributor and above, once permitted)

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-17005 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-17005

UNKNOWNCVSS 0NVD feed

Published 4 October 2026 · tracked since 4 October 2026

Description

The Horizontal scrolling announcements WordPress plugin through 2.6 does not sanitise and escape one of its announcement settings before outputting it into an attribute context on the front end, allowing users granted access to the announcement management page (Contributor and above, once permitted)

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]