Description
The WP Meteor Website Speed Optimization Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 3.4.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is delivered via the comment author name field, which must clear WordPress's comment moderation workflow before being displayed, though this represents a display prerequisite rather than any sanitization control.
Published: 2026-10-10
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw that lets an unauthenticated attacker inject arbitrary scripts into the comment author name field of the WP Meteor plugin. If a comment is processed through WordPress moderation and later displayed, the injected payload will execute in the browsers of site visitors, potentially allowing theft of session cookies, credential compromise, or site defacement. The problem stems from insufficient input sanitization and output escaping within the plugin.

Affected Systems

This issue affects the WP Meteor Website Speed Optimization Addon (vendor aguidrevitch) for all releases up to and including version 3.4.18 running on WordPress sites. Any site that uses this plugin version and accepts anonymous or unauthenticated comments is susceptible.

Risk and Exploitability

The flaw carries a CVSS score of 7.2, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the weakness by submitting a comment that later passes moderation; therefore, the primary vector is the web comment interface, and the attack requires unauthenticated access to the comment form plus a moderation clearance step. Given the lack of a mitigation in the EPSS and KEV, the risk rests on the plugin’s popularity and the likelihood of comment submissions.

Generated by OpenCVE AI on October 10, 2026 at 08:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the WP Meteor plugin to the latest secure version.
  • If an upgrade is not feasible, disable the comment author name field or remove the plugin’s comment handling features.
  • Implement strict input validation and output encoding for the comment author name field to prevent script injection.

Generated by OpenCVE AI on October 10, 2026 at 08:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:00:00 +0000

Type Values Removed Values Added
Description The WP Meteor Website Speed Optimization Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 3.4.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is delivered via the comment author name field, which must clear WordPress's comment moderation workflow before being displayed, though this represents a display prerequisite rather than any sanitization control.
Title WP Meteor Website Speed Optimization Addon <= 3.4.18 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T06:40:16.314Z

Reserved: 2026-09-23T13:25:43.487Z

Link: CVE-2026-96572

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T07:16:42.487

Modified: 2026-10-10T07:16:42.487

Link: CVE-2026-96572

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T08:45:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')