Sceawere
Vulnerability Detail
CVE-2026-96572UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WP Meteor Stored XSS Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 3h ago
- Vendor
- aguidrevitch
- Product
- WP Meteor Website Speed Optimization Addon
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The WP Meteor Website Speed Optimization Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 3.4.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is delivered via the comment author name field, which must clear WordPress's comment moderation workflow before being displayed, though this represents a display prerequisite rather than any sanitization control.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-10T07:16:42.487Z",
"pubdate": "2026-10-10T07:16:42.487Z",
"executiveSummary": "The WP Meteor Website Speed Optimization Addon for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability affecting all versions up to and including 3.4.18.\nThis flaw arises from inadequate input sanitization and output escaping mechanisms within the plugin's handling of the comment author name field.\nUnauthenticated attackers can inject malicious JavaScript payloads into the comment author field, which are subsequently stored in the site database.\nWhen an administrator or user views the comment section, the stored payload executes within their browser context, potentially leading to unauthorized actions, session hijacking, or the defacement of the web page.\nWhile the payload must pass through the WordPress comment moderation queue, this acts only as a procedural step rather than a security control, meaning the vulnerability remains accessible to any actor capable of submitting a comment.\nThe risk is significant as it permits the execution of arbitrary scripts on behalf of authenticated users, undermining the security posture of the affected WordPress site.",
"technicalDetails": "The root cause of this vulnerability is the failure of the WP Meteor Website Speed Optimization Addon to properly sanitize user-supplied data in the 'comment author name' field before storing it in the database and failing to implement context-aware output escaping when rendering this data on the frontend.\nThe vulnerable component involves the plugin's processing logic for displaying comment metadata, which blindly trusts the integrity of the database entries associated with comment author names.\nExploitation is achieved through an unauthenticated injection vector. An attacker submits a comment using a crafted string in the author name field, where the string contains malicious HTML tags and JavaScript, such as '<script>alert(1)</script>'.\nBecause the plugin does not enforce strict input validation or sanitization, this malicious payload is persisted in the WordPress database table associated with comments.\nThe attack flow follows these stages: First, the attacker identifies the comment submission form on a publicly accessible page. Second, the attacker submits a comment, populating the 'author name' field with a JavaScript payload. Third, the submission reaches the site's comment moderation queue. Fourth, once a moderator or administrator approves the comment, the payload becomes active within the public comment section.\nWhen any user, including high-privileged administrators, views a page where this comment is displayed, the browser interprets the stored script as legitimate code. Consequently, the script executes within the security context of the user's session.\nThis allows for post-exploitation impacts such as the theft of session cookies, the execution of arbitrary administrative actions (if the target is an administrator), unauthorized redirects, or the exfiltration of sensitive information presented on the affected page.\nThe vulnerability affects all versions up to 3.4.18 and requires no specific authentication, making it a persistent threat to any WordPress deployment using the plugin with enabled comment functionality.\nThe lack of output escaping prevents the browser from distinguishing between expected text content and executable script blocks, thus allowing the injection of arbitrary web scripts."
}