Stored Cross-Site Scripting Vulnerability in Cute News Ticker for WordPress
CVE-2025-13656
6.4MEDIUM
What is CVE-2025-13656?
The Cute News Ticker plugin for WordPress has a significant vulnerability that allows authenticated attackers with Contributor-level access or higher to inject malicious web scripts via the 'color' shortcode attribute. Due to inadequate input sanitization and output escaping, these scripts can execute when a user visits any page that has been compromised, thereby posing a serious risk to website integrity and user data.
Affected Version(s)
Cute News Ticker * <= 1.0