Description
The GSpeech TTS – WordPress Text To Speech Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.22.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This mXSS-style transform bypasses WordPress comment kses sanitization because the payload is stored using only kses-allowed tags and attributes; the malicious event handlers and style fragments become active only when the plugin's output-buffer callback rewrites the rendered HTML at request time.
Published: 2026-10-02
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows unauthenticated attackers to store malicious JavaScript in comment content that is later executed when a page is rendered. The stored XSS can hijack user sessions, deface content, or redirect visitors. It is rated high severity with a CVSS score of 7.2, indicating significant impact if exploited.

Affected Systems

The issue affects the GSpeech TTS WordPress plugin in all releases up to and including version 3.22.0. Any WordPress installation that has this plugin and accepts comments is susceptible; the vulnerability is confined to the plugin’s rendering context and does not extend to core WordPress.

Risk and Exploitability

Attackers can submit the exploit payload without needing authentication by posting a specially crafted comment. The injected content is stored and later rewritten by the plugin’s output‑buffer callback, enabling script execution. The exploit is not listed in the CISA KEV catalog and the EPSS score is unavailable, but the high CVSS score signals a serious risk that could be leveraged if discovered.

Generated by OpenCVE AI on October 2, 2026 at 08:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the GSpeech TTS plugin to the latest version (3.23 or newer).
  • After updating, scan for and delete any comments containing unexpected tags or script code.
  • If an immediate update is not possible, disable comments or remove the plugin entirely until a patch is applied.

Generated by OpenCVE AI on October 2, 2026 at 08:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Description The GSpeech TTS – WordPress Text To Speech Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.22.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This mXSS-style transform bypasses WordPress comment kses sanitization because the payload is stored using only kses-allowed tags and attributes; the malicious event handlers and style fragments become active only when the plugin's output-buffer callback rewrites the rendered HTML at request time.
Title GSpeech TTS <= 3.22.0 - Unauthenticated Stored Cross-Site Scripting via Comment Content
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-02T07:39:21.086Z

Reserved: 2026-09-23T13:36:50.599Z

Link: CVE-2026-96578

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T08:17:04.477

Modified: 2026-10-02T08:17:04.477

Link: CVE-2026-96578

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T08:45:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')