Skip to content
Noroxi

Stock Ticker

stock-ticker · plugin

Known security vulnerabilities for Stock Ticker. Find out in seconds which version runs on your site with WP Lens.

6 known vulnerabilities

3 exploitable without logging in · 2 with public exploit code · latest Mar 6, 2026

Listed on wordpress.org · latest 3.26.2 · last updated Mar 4, 2026 · 2K+ installs

wordpress.org status checked on Oct 2, 2026

Vulnerabilities

  • CVE-2022-45365unauthenticated · needs a click≤ 3.23.2

    WordPress Stock Ticker Plugin <= 3.23.2 is vulnerable to Cross Site Scripting (XSS)

    Medium 6.1
  • CVE-2023-40208unauthenticated · needs a click≤ 3.23.3

    WordPress Stock Ticker Plugin <= 3.23.3 is vulnerable to Cross Site Scripting (XSS)

    Medium 6.1
  • CVE-2023-51541login required≤ 3.23.4

    WordPress Stock Ticker Plugin <= 3.23.4 is vulnerable to Cross Site Scripting (XSS)

    Medium 5.4
  • CVE-2024-6363contributor+≤ 3.24.4

    Stock Ticker <= 3.24.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via stock_ticker Shortcode

    Medium 5.4
  • CVE-2023-27626unauthenticated≤ 3.23.0

    WordPress Stock Ticker plugin <= 3.23.0 - Broken Access Control vulnerability

    Medium 5.3
  • CVE-2026-2722admin≤ 3.26.1

    Stock Ticker <= 3.26.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via Template

    Medium 4.8

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory