Description
The Web Vitals Tracking WordPress plugin through 5.4.2 does not validate or escape performance measurements submitted by unauthenticated visitors before storing them and outputting them in a script context on an administrative page, allowing unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators.
Published: 2026-10-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored cross‑site scripting against administrators
Action: Immediate Patch
AI Analysis

Impact

The Web Vitals Tracking WordPress plugin, as distributed through version 5.4.2 and earlier, fails to validate or escape performance data sent by unauthenticated visitors. Because the beacon metric name is stored and later rendered into a script tag on an administrative page, attackers can inject arbitrary JavaScript that executes with the privileges of the site administrator. This stored cross‑site scripting can be used to hijack admin sessions, deface the site, or execute further malicious actions from the admin interface. No authentication is required to submit the payload, so the vulnerability is wide open to any web visitor.

Affected Systems

Any site running the Web Vitals Tracking WordPress plugin with a version of 5.4.2 or earlier is potentially affected. The vendor is listed simply as Web Vitals Tracking on WordPress.org; no other vendors or product families are reported. No specific CPE strings are provided, but the vulnerability applies to the plugin code itself.

Risk and Exploitability

The vulnerability is a classic stored XSS (CWE‑79), which offers a high likelihood of exploitation when an attacker can submit arbitrary metric names. The attack vector is purely web‑based and does not require prior authentication, so any user can trigger the flaw. While no CVSS score or EPSS value is supplied, stored XSS in an admin area typically receives a medium to high severity rating. The vulnerability is not currently listed in CISA’s KEV catalog, indicating no confirmed large‑scale exploitation reports to date, but the critical nature of the admin context warrants immediate attention.

Generated by OpenCVE AI on October 11, 2026 at 07:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Web Vitals Tracking plugin to the latest stable release (any version greater than 5.4.2).
  • Configure the plugin or host to reject or sanitize incoming beacon metric names from unauthenticated requests, ensuring they are stored only after proper escaping or removal of script‑containing characters.
  • Deploy a web application firewall rule to block or neutralize XSS payloads submitted to the beacon endpoint before they reach the plugin storage layer.

Generated by OpenCVE AI on October 11, 2026 at 07:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 11 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sun, 11 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Web Vitals Tracking WordPress plugin through 5.4.2 does not validate or escape performance measurements submitted by unauthenticated visitors before storing them and outputting them in a script context on an administrative page, allowing unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators.
Title Web Vitals Tracking <= 5.4.2 - Unauthenticated Stored XSS via Tracking Beacon Metric Name
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-11T11:32:43.617Z

Reserved: 2026-09-09T07:22:39.450Z

Link: CVE-2026-87760

cve-icon Vulnrichment

Updated: 2026-10-11T11:22:51.749Z

cve-icon NVD

Status : Received

Published: 2026-10-11T07:17:26.573

Modified: 2026-10-11T12:17:24.943

Link: CVE-2026-87760

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T07:45:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')