CVE-2019-7413: Parallax Scroll Project Parallax Scroll

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

In the Parallax Scroll (aka adamrob-parallax-scroll) plugin before 2.1 for WordPress, includes/adamrob-parralax-shortcode.php allows XSS via the title text. ("parallax" has a spelling change within the PHP filename.)

Affected products

Published 2019-02-05. Last modified 2026-06-17.