VYPR

News Announcement Scroll

by Storeapps

Source repositories

CVEs (2)

  • CVE-2023-5663HigMar 13, 2024
    risk 0.50cvss 8.8epss 0.01

    The News Announcement Scroll plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…

  • CVE-2022-40694Nov 17, 2022
    risk 0.00cvss epss 0.00

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in News Announcement Scroll plugin <= 8.8.8 on WordPress.