CVE-2026-8701 PUBLISHED

GNTT Post Title Ticker <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

Assigner: Wordfence
Reserved: 15.05.2026 Published: 27.05.2026 Updated: 27.05.2026

The GNTT Post Title Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the title-ticker-slide, title-ticker-fade, and title-ticker-typing shortcodes. This is due to insufficient input sanitization and output escaping on shortcode attributes (notably border, width, height, header_background, header_text_color, and id) within the gntt_title_ticker_slide(), gntt_title_ticker_fade(), and gntt_title_ticker_typing() functions. None of these attribute values are passed through esc_attr() or any other escaping function before being concatenated into HTML output. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
CVSS Score: 6.4

Product Status

Vendor golzarrahman
Product GNTT Post Title Ticker
Versions Default: unaffected
  • affected from 0 to 1.0 (incl.)

Credits

  • nail majdeddine finder

References

Problem Types

  • CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE