Impact
The Web Vitals Tracking WordPress plugin, as distributed through version 5.4.2 and earlier, fails to validate or escape performance data sent by unauthenticated visitors. Because the beacon metric name is stored and later rendered into a script tag on an administrative page, attackers can inject arbitrary JavaScript that executes with the privileges of the site administrator. This stored cross‑site scripting can be used to hijack admin sessions, deface the site, or execute further malicious actions from the admin interface. No authentication is required to submit the payload, so the vulnerability is wide open to any web visitor.
Affected Systems
Any site running the Web Vitals Tracking WordPress plugin with a version of 5.4.2 or earlier is potentially affected. The vendor is listed simply as Web Vitals Tracking on WordPress.org; no other vendors or product families are reported. No specific CPE strings are provided, but the vulnerability applies to the plugin code itself.
Risk and Exploitability
The vulnerability is a classic stored XSS (CWE‑79), which offers a high likelihood of exploitation when an attacker can submit arbitrary metric names. The attack vector is purely web‑based and does not require prior authentication, so any user can trigger the flaw. While no CVSS score or EPSS value is supplied, stored XSS in an admin area typically receives a medium to high severity rating. The vulnerability is not currently listed in CISA’s KEV catalog, indicating no confirmed large‑scale exploitation reports to date, but the critical nature of the admin context warrants immediate attention.
OpenCVE Enrichment