Stored Cross-Site Scripting Vulnerability in WP Meteor Website Speed Optimization Addon for WordPress
CVE-2026-96572

7.2HIGH

What is CVE-2026-96572?

The WP Meteor Website Speed Optimization Addon plugin for WordPress is subject to a Stored Cross-Site Scripting vulnerability that arises from inadequate input sanitization and output escaping in the comment author name field. All versions up to and including 3.4.18 are affected. This vulnerability enables unauthenticated attackers to inject malicious web scripts into comment submissions, which can then be executed when users view the impacted pages. Although the comment author name must pass through WordPress's moderation system before appearing publicly, it does not guarantee that the input is properly sanitized, allowing for potential exploitation.

Affected Version(s)

WP Meteor Website Speed Optimization Addon 0 <= 3.4.18

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

theviper17y
.