Stored Cross-Site Scripting Vulnerability in WP Meteor Website Speed Optimization Addon for WordPress
CVE-2026-96572
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-96572?
The WP Meteor Website Speed Optimization Addon plugin for WordPress is subject to a Stored Cross-Site Scripting vulnerability that arises from inadequate input sanitization and output escaping in the comment author name field. All versions up to and including 3.4.18 are affected. This vulnerability enables unauthenticated attackers to inject malicious web scripts into comment submissions, which can then be executed when users view the impacted pages. Although the comment author name must pass through WordPress's moderation system before appearing publicly, it does not guarantee that the input is properly sanitized, allowing for potential exploitation.
Affected Version(s)
WP Meteor Website Speed Optimization Addon 0 <= 3.4.18