Sceawere

Vulnerability Detail

CVE-2026-96578UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

GSpeech Stored Cross-Site Scripting

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
15h ago
Vendor
creative-solutions-1
Product
GSpeech TTS – WordPress Text To Speech Plugin
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The GSpeech TTS – WordPress Text To Speech Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.22.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This mXSS-style transform bypasses WordPress comment kses sanitization because the payload is stored using only kses-allowed tags and attributes; the malicious event handlers and style fragments become active only when the plugin's output-buffer callback rewrites the rendered HTML at request time.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-02T08:17:04.477Z",
  "pubdate": "2026-10-02T08:17:04.477Z",
  "executiveSummary": "The GSpeech TTS – WordPress Text To Speech Plugin, in versions up to and including 3.22.0, contains a critical Stored Cross-Site Scripting (XSS) vulnerability.\nThis vulnerability stems from inadequate sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts into WordPress comments.\nThe malicious payload successfully bypasses the native WordPress kses sanitization filters by utilizing permitted tags and attributes. The payload is later triggered through a mutation XSS (mXSS) process when the plugin's output-buffer callback modifies the rendered HTML at request time.\nSuccessful exploitation enables unauthenticated attackers to execute malicious JavaScript within the browsers of visitors or administrative users who view the compromised page.\nThe potential impact includes session hijacking, unauthorized actions on behalf of the victim, and the delivery of further malicious content.\nThe vulnerability represents a significant security risk, as it does not require authentication to trigger and leverages a transformation mechanism that renders standard security filters ineffective against the crafted payload.",
  "technicalDetails": "The vulnerability resides within the processing logic of the GSpeech TTS plugin, specifically where it intercepts and modifies HTML output via an output-buffer callback.\nThe root cause is a failure to properly sanitize and escape user-supplied data within comment content. While WordPress employs the kses library to strip malicious tags and attributes from submitted comments, the plugin's architecture allows for a bypass. Attackers craft payloads using only tags and attributes that are explicitly whitelisted by kses, ensuring the malicious code is stored in the database.\nThe exploit mechanism functions as an mXSS (mutation XSS) attack. When the plugin processes the stored comment for display, its output-buffer callback performs a post-processing transformation on the rendered HTML. During this rewrite phase, the carefully structured, benign-looking tags and attributes are mutated into active HTML elements containing malicious event handlers or style-based execution vectors that were previously dormant.\nThe attack flow begins with an unauthenticated attacker submitting a crafted comment. This comment contains valid, kses-approved HTML fragments that house the latent payload. Upon submission, the payload is committed to the WordPress database. When a user subsequently visits the page containing the injected comment, the plugin initiates its output-buffer callback to rewrite the HTML content for TTS rendering. This process inadvertently triggers the mutation, activating the malicious script embedded in the comment.\nBecause this occurs in the client's browser context during page rendering, the script executes with the permissions of the viewing user. If an administrator views the page, the attacker can leverage the script to perform administrative actions, such as creating new user accounts, modifying plugin settings, or exfiltrating sensitive session tokens.\nThe vulnerability affects all plugin versions up to and including 3.22.0. No authentication is required for exploitation, and the attack is reachable over the network via standard public-facing comment forms. The reliance on output buffering to process rendered content serves as the primary technical vector for the vulnerability, demonstrating the dangers of performing insecure HTML transformations after primary sanitization has already occurred."
}
CVE-2026-96578: GSpeech Stored Cross-Site Scripting (HIGH Severity, CVSS: 7.2) | Sceawere