Stored Cross-Site Scripting Vulnerability in GSpeech TTS WordPress Plugin
CVE-2026-96578

7.2HIGH

What is CVE-2026-96578?

The GSpeech TTS – WordPress Text To Speech Plugin is affected by a vulnerability that allows stored cross-site scripting through comment content. This flaw arises from inadequate input sanitization and output escaping in versions up to and including 3.22.0. Attackers can exploit this vulnerability by injecting malicious web scripts that execute when a user loads the compromised page. The attack circumvents WordPress's standard comment sanitization processes, as the payload includes only tags and attributes deemed safe. However, malicious event handlers and styling elements activate due to the plugin's output-buffer behavior, posing a significant risk to unsuspecting users.

Affected Version(s)

GSpeech TTS – WordPress Text To Speech Plugin 0 <= 3.22.0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

theviper17y
.