CVE-2026-6710 Details
Description
The Skysa Text Ticker App plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the SkysaApps_Admin_AppPage function. This makes it possible for unauthenticated attackers to trick a site administrator into making a forged request to modify the plugin's settings, including the scrolling message text and URL, via a forged cross-site request via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Skysa Text Ticker App plugin for WordPress, affecting all versions through 1.4. The vulnerability arises from inadequate nonce validation in the SkysaApps_Admin_AppPage function, allowing unauthenticated attackers to manipulate a site administrator into unintentionally changing the plugin's settings. This includes altering the scrolling message text and URL, by exploiting the lack of proper request validation and tricking the administrator into clicking a link that initiates the forged request.
There is no known patch available for this vulnerability. It is recommended to review the vulnerability details thoroughly and consider uninstalling the affected plugin.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 12, 2026CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://plugins.trac.wordpress.org/browser/skysa-text-ticker-app/tags/1.4/skysa-required/admin.php#L215 | [email protected] | Broken LinkSource CodeVendor |
| https://plugins.trac.wordpress.org/browser/skysa-text-ticker-app/tags/1.4/skysa-required/admin.php#L281 | [email protected] | Broken LinkSource CodeVendor |
| https://plugins.trac.wordpress.org/browser/skysa-text-ticker-app/trunk/skysa-required/admin.php#L215 | [email protected] | Broken LinkSource CodeVendor |
| https://plugins.trac.wordpress.org/browser/skysa-text-ticker-app/trunk/skysa-required/admin.php#L281 | [email protected] | Broken LinkSource CodeVendor |
| https://www.wordfence.com/threat-intel/vulnerabilities/id/bcd5b83a-7d51-455b-bb31-dd776264fc6b?source=cve | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Skysa Text Ticker App | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 12, 2026 | New CVE Received | [email protected] |
Volerion