Stored Cross-Site Scripting Vulnerability in GSpeech TTS WordPress Plugin
CVE-2026-96578
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 October 2026
What is CVE-2026-96578?
The GSpeech TTS β WordPress Text To Speech Plugin is affected by a vulnerability that allows stored cross-site scripting through comment content. This flaw arises from inadequate input sanitization and output escaping in versions up to and including 3.22.0. Attackers can exploit this vulnerability by injecting malicious web scripts that execute when a user loads the compromised page. The attack circumvents WordPress's standard comment sanitization processes, as the payload includes only tags and attributes deemed safe. However, malicious event handlers and styling elements activate due to the plugin's output-buffer behavior, posing a significant risk to unsuspecting users.
Affected Version(s)
GSpeech TTS β WordPress Text To Speech Plugin 0 <= 3.22.0