Impact
The vulnerability is an unauthenticated XSS flaw that allows an attacker to inject arbitrary JavaScript into the pages of a WordPress site that uses the Core Web Vitals & PageSpeed Booster plugin. The flaw is present in all releases of the plugin up to and including 1.0.31 and can be triggered by a visitor without administrative credentials, enabling session hijacking, defacement, or malicious redirects. The weakness is a classic input‑validation error (CWE‑79).
Affected Systems
All WordPress installations that have the Core Web Vitals & PageSpeed Booster plugin version 1.0.31 or earlier are affected. The plugin is distributed by Mohammed Kaludi and is intended for use on WordPress sites to improve Core Web Vitals and PageSpeed metrics. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS base score is 7.1, indicating high severity. The EPSS score is currently not available, and the issue is not listed in the CISA KEV catalog. Because the flaw is exploitable without authentication, any visitor could run malicious code on the site, posing a significant risk to confidentiality, integrity, and availability of the website and its users.
OpenCVE Enrichment