Executive brief
The Skysa Text Ticker App plugin for WordPress, which displays scrolling text messages on websites, contains a security flaw that could allow an attacker to change the plugin's settings. By tricking a site administrator into clicking a malicious link, an attacker can remotely modify the scrolling message text and associated links. This could be used to display unauthorized content or redirect visitors to malicious websites.
Technical details
The Skysa Text Ticker App plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation on the SkysaApps_Admin_AppPage function. This vulnerability exists in all versions up to and including 1.4. An unauthenticated attacker can exploit this by inducing a site administrator to perform an action, such as clicking a link, which triggers a forged request. Successful exploitation allows the attacker to modify the plugin's settings, specifically the scrolling message text and the destination URL. This is a classic CSRF vulnerability where the application fails to verify that a sensitive administrative request was intentionally initiated by the user.
Affected products
- SkysaApps Skysa Text Ticker App Up to, and including, 1.4
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory
References
- https://plugins.trac.wordpress.org/browser/skysa-text-ticker-app/tags/1.4/skysa-required/admin.php
- https://plugins.trac.wordpress.org/browser/skysa-text-ticker-app/tags/1.4/skysa-required/admin.php
- https://plugins.trac.wordpress.org/browser/skysa-text-ticker-app/trunk/skysa-required/admin.php
- https://plugins.trac.wordpress.org/browser/skysa-text-ticker-app/trunk/skysa-required/admin.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/bcd5b83a-7d51-455b-bb31-dd776264fc6b?source=cve