Stored Cross-Site Scripting Vulnerability in WP Meteor Website Speed Optimization Addon for WordPress
CVE-2026-2902

6.1MEDIUM

What is CVE-2026-2902?

The WP Meteor Website Speed Optimization Addon plugin for WordPress is prone to Stored Cross-Site Scripting attacks through the 'frontend_rewrite' function. Due to inadequate input sanitization and output escaping practices, attackers can exploit the placeholder content 'WPMETEOR[N]WPMETEOR' to inject arbitrary scripts. This vulnerability affects all versions up to and including 3.4.16, allowing attackers to execute malicious scripts in the browsers of users who access compromised pages.

Affected Version(s)

WP Meteor Website Speed Optimization Addon 0 <= 3.4.16

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Yudha - DJ
.