Impact
The vulnerability is a stored cross‑site scripting flaw that lets an unauthenticated attacker inject arbitrary scripts into the comment author name field of the WP Meteor plugin. If a comment is processed through WordPress moderation and later displayed, the injected payload will execute in the browsers of site visitors, potentially allowing theft of session cookies, credential compromise, or site defacement. The problem stems from insufficient input sanitization and output escaping within the plugin.
Affected Systems
This issue affects the WP Meteor Website Speed Optimization Addon (vendor aguidrevitch) for all releases up to and including version 3.4.18 running on WordPress sites. Any site that uses this plugin version and accepts anonymous or unauthenticated comments is susceptible.
Risk and Exploitability
The flaw carries a CVSS score of 7.2, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the weakness by submitting a comment that later passes moderation; therefore, the primary vector is the web comment interface, and the attack requires unauthenticated access to the comment form plus a moderation clearance step. Given the lack of a mitigation in the EPSS and KEV, the risk rests on the plugin’s popularity and the likelihood of comment submissions.
OpenCVE Enrichment