Stored Cross-Site Scripting in GNTT Post Title Ticker Plugin for WordPress
CVE-2026-8701
6.4MEDIUM
What is CVE-2026-8701?
The GNTT Post Title Ticker plugin for WordPress contains a vulnerability allowing authenticated attackers to exploit insufficient input sanitization and output escaping. This flaw exists in specific shortcode attributes within key functions, enabling the injection of arbitrary web scripts that execute in the user's browser when accessing affected pages.
Affected Version(s)
GNTT Post Title Ticker 0 <= 1.0