Sceawere

Vulnerability Detail

CVE-2026-87760UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stored XSS in Web Vitals

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
8h ago
Vendor
Unknown
Product
Web Vitals Tracking
Attack Type
CWE-79 Cross-Site Scripting (XSS)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The Web Vitals Tracking WordPress plugin through 5.4.2 does not validate or escape performance measurements submitted by unauthenticated visitors before storing them and outputting them in a script context on an administrative page, allowing unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-10-11T07:17:26.573Z",
  "pubdate": "2026-10-11T07:17:26.573Z",
  "executiveSummary": "The Web Vitals Tracking WordPress plugin is affected by a Stored Cross-Site Scripting (XSS) vulnerability in versions up to and including 5.4.2.\nThe vulnerability arises from the failure to properly validate or sanitize performance data submitted by unauthenticated users via the plugin's telemetry mechanisms.\nBecause this data is stored and subsequently rendered within a script context on an administrative dashboard page, unauthenticated attackers can inject malicious JavaScript payloads.\nSuccessful exploitation allows an attacker to execute arbitrary code within the session of an authenticated administrator, potentially leading to unauthorized administrative actions, session hijacking, or site compromise.\nThe vulnerability requires no authentication to trigger, as the input collection endpoint is exposed to public visitors. Mitigation is essential to prevent malicious actors from leveraging the plugin as a vector for administrative account takeover.",
  "technicalDetails": "The root cause of this vulnerability is an improper implementation of input sanitization and output encoding within the Web Vitals Tracking plugin. The plugin tracks performance metrics by accepting data payloads from the client side; however, it fails to enforce strict validation or whitelist-based sanitization on the fields submitted to the backend.\nWhen an unauthenticated visitor interacts with the site, the plugin processes performance measurements. Because these measurements are stored directly into the WordPress database without escaping, the database becomes a vector for persistent malicious scripts.\nThe exploitation process follows a predictable flow: first, an unauthenticated attacker crafts a malicious payload containing JavaScript, such as a script tag or an event handler attribute, disguised as a performance metric. This payload is transmitted to the plugin's telemetry endpoint. The plugin accepts this input and stores it persistently in the database.\nThe secondary phase of the attack occurs when an administrator accesses the plugin's administrative reporting interface. The plugin retrieves the stored telemetry data and reflects it directly into the HTML document, specifically within a script context. Because the output lacks context-aware encoding, the browser interprets the attacker's stored payload as executable code rather than plain text.\nThe execution of this injected JavaScript occurs within the security context of the administrative user. This allows the attacker to perform actions on behalf of the administrator, such as creating new rogue accounts, modifying plugin settings, or exfiltrating sensitive session cookies via document.cookie access. Given that the administrative dashboard often manages critical site infrastructure, the impact is significant, potentially leading to full site compromise if the injected script interacts with other high-privilege administrative functions."
}
CVE-2026-87760: Stored XSS in Web Vitals (HIGH Severity, CVSS: 8.8) | Sceawere