Impact
The Speed Optimizer – The All-In-One Performance-Boosting Plugin for WordPress is vulnerable to a stored cross‑site scripting flaw through image tag attributes. Insufficient input sanitization and output escaping allow authenticated users with contributor privileges and higher to insert arbitrary JavaScript into image tags that are stored in the database. When a page containing the affected image is viewed, the injected script executes in the visitor’s browser. This vulnerability is only exploitable when the site administrator has enabled the Lazy Load Media option in the plugin settings.
Affected Systems
WordPress sites that are running SiteGround Speed Optimizer plugin version 7.8.0 or earlier and have the Lazy Load Media option turned on are affected. Versions 7.8.1 and later are not impacted.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog. Because exploitation requires an authenticated contributor or higher, only insiders or compromised accounts can leverage the flaw. Once executed, the stored script could affect any visitor to the affected page, creating a risk to confidentiality and integrity for that site’s users.
OpenCVE Enrichment