Stored Cross-Site Scripting Vulnerability in WP Meteor Website Speed Optimization Addon for WordPress
CVE-2026-2902
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 29 April 2026
What is CVE-2026-2902?
The WP Meteor Website Speed Optimization Addon plugin for WordPress is prone to Stored Cross-Site Scripting attacks through the 'frontend_rewrite' function. Due to inadequate input sanitization and output escaping practices, attackers can exploit the placeholder content 'WPMETEOR[N]WPMETEOR' to inject arbitrary scripts. This vulnerability affects all versions up to and including 3.4.16, allowing attackers to execute malicious scripts in the browsers of users who access compromised pages.
Affected Version(s)
WP Meteor Website Speed Optimization Addon 0 <= 3.4.16