Junglewise Threat Intelligence

CVE-2026-8701: GNTT Post Title Ticker Stored XSS in shortcodes

CVE-2026-8701 · Severity: medium · CVSS 6.4 · Published 2026-05-27

Executive brief

The GNTT Post Title Ticker plugin for WordPress, which displays scrolling or animated post titles, contains a security flaw that allows users with contributor-level access to inject malicious scripts into website pages. These scripts execute automatically when other users, including site administrators, view the affected pages. This could lead to unauthorized actions being performed on behalf of other users or the theft of sensitive session information.

Technical details

The GNTT Post Title Ticker plugin for WordPress (v1.0) is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on shortcode attributes. Specifically, the functions `gntt_title_ticker_slide()`, `gntt_title_ticker_fade()`, and `gntt_title_ticker_typing()` fail to use `esc_attr()` or similar escaping functions on attributes such as 'border', 'width', 'height', 'header_background', 'header_text_color', and 'id'. An authenticated attacker with contributor-level permissions or higher can exploit this by embedding malicious scripts within these attributes. The scripts are then stored and executed in the context of any user's browser who views the page containing the malicious shortcode.

Affected products

  • GNTT GNTT Post Title Ticker 1.0

Timeline

  • 2026-05-27: disclosed: Initial disclosure by Wordfence
  • 2026-05-27: advisory: NVD publication date

References