plugin

Stock Ticker Vulnerabilities

12 known security issues reported for the Stock Ticker WordPress plugin. Most recent disclosed Mar 7, 2026.

7 medium

Running Stock Ticker on your site? Check whether your installed version is affected.

Scan your site free

Stock Ticker - Authenticated (Administrator+) Stored Cross-Site Scripting via Template vulnerability

medium

Authenticated (Administrator+) Stored Cross-Site Scripting via Template vulnerability

CVSS:
5.9
Affected:
up to 3.26.1
Fixed in:
3.26.2
Disclosed:
Mar 7, 2026

Stock Ticker <= 3.26.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via Template

medium

The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.26.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arb...

CVSS:
4.8
Affected:
up to 3.26.1
Fixed in:
3.26.2
Disclosed:
Mar 6, 2026

CVE-2026-2722 on NVD →

Stock Ticker [stock-ticker] < 3.23.1

unknown

[en] Missing Authorization vulnerability in Aleksandar Urošević Stock Ticker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stock Ticker: from n/a through 3.23.0.

Affected:
up to 3.23.1
Fixed in:
3.23.1
Disclosed:
Dec 9, 2024

CVE-2023-27626 on NVD →

Stock Ticker [stock-ticker] < 3.24.6

unknown

[en] The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's stock_ticker shortcode in all versions up to, and including, 3.24.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with co...

Affected:
up to 3.24.6
Fixed in:
3.24.6
Disclosed:
Jun 29, 2024

CVE-2024-6363 on NVD →

Stock Ticker <= 3.24.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via stock_ticker Shortcode

medium

The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's stock_ticker shortcode in all versions up to, and including, 3.24.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contrib...

CVSS:
6.4
Affected:
up to 3.24.4
Fixed in:
3.24.6
Disclosed:
Jun 28, 2024

CVE-2024-6363 on NVD →

Stock Ticker [stock-ticker] < 3.23.5

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aleksandar Urošević Stock Ticker allows Stored XSS.This issue affects Stock Ticker: from n/a through 3.23.4.

Affected:
up to 3.23.5
Fixed in:
3.23.5
Disclosed:
Dec 29, 2023

CVE-2023-51541 on NVD →

Stock Ticker <= 3.23.4 - Authenticated (Contributor+) Stored Cross-Site Scritping

medium

The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.23.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to injec...

CVSS:
6.4
Affected:
up to 3.23.4
Fixed in:
3.23.5
Disclosed:
Dec 27, 2023

CVE-2023-51541 on NVD →

Stock Ticker [stock-ticker] < 3.23.3

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aleksandar Urošević Stock Ticker allows Reflected XSS.This issue affects Stock Ticker: from n/a through 3.23.2.

Affected:
up to 3.23.3
Fixed in:
3.23.3
Disclosed:
Dec 14, 2023

CVE-2022-45365 on NVD →

Stock Ticker [stock-ticker] < 3.23.4

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Aleksandar Urošević Stock Ticker plugin <= 3.23.3 versions.

Affected:
up to 3.23.4
Fixed in:
3.23.4
Disclosed:
Sep 4, 2023

CVE-2023-40208 on NVD →

Stock Ticker <= 3.23.3 - Reflected Cross-Site Scripting in ajax_stockticker_load

medium

The Stock Ticker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in the ajax_stockticker_load function in versions up to, and including, 3.23.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages t...

CVSS:
6.1
Affected:
up to 3.23.3
Fixed in:
3.23.4
Disclosed:
Aug 11, 2023

CVE-2023-40208 on NVD →

Stock Ticker <= 3.23.2 - Reflected Cross-Site Scripting in ajax_stockticker_symbol_search_test

medium

The Stock Ticker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in the ajax_stockticker_symbol_search_test function in versions up to, and including, 3.23.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scri...

CVSS:
6.1
Affected:
up to 3.23.2
Fixed in:
3.23.3
Disclosed:
Aug 10, 2023

CVE-2022-45365 on NVD →

Stock Ticker <= 3.23.0 - Missing Authorization via AJAX actions

medium

The Stock Ticker plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check on several AJAX actions in versions up to, and including, 3.23.0. This makes it possible for unauthenticated attackers to change plugin settings.

CVSS:
4.3
Affected:
up to 3.23.0
Fixed in:
3.23.1
Disclosed:
Mar 13, 2023

CVE-2023-27626 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database