Skip to content
Threat Feed
high advisory

Stored Cross-Site Scripting in WP Meteor Website Speed Optimization Addon

The WP Meteor Website Speed Optimization Addon for WordPress versions 3.4.18 and earlier contains a Stored XSS vulnerability allowing unauthenticated attackers to inject malicious scripts via the comment author name field.

CVE search metadata

CVE search record: CVE-2026-96572. Severity: high. CVSS: 7.2. KEV: no. Product: WP Meteor Website Speed Optimization Addon (<= 3.4.18). Brief: Stored Cross-Site Scripting in WP Meteor Website Speed Optimization Addon. Brief link: https://feed.craftedsignal.io/briefs/2026-10-wp-meteor-xss/

The WP Meteor Website Speed Optimization Addon plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability impacting all versions up to and including 3.4.18. The flaw arises from insufficient input sanitization and output escaping within the comment author name field. An unauthenticated attacker can supply a crafted payload containing malicious JavaScript as the comment author name. While the comment must bypass the site's moderation workflow to be displayed, the application fails to safely process the input, resulting in the script executing in the browser of any user who views the page where the comment is rendered. This vulnerability presents a high risk for account takeover, session hijacking, or site redirection when administrators or authenticated users interact with the infected comments section.

Impact

Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of the victim's browser session. Depending on the privileges of the user viewing the compromised page, this can lead to administrative account takeover, unauthorized modification of site content, or the injection of further malicious redirects and phishing content. The impact is significant for site integrity and user security, as it affects the frontend display of comments across the WordPress installation.

Recommendation

Prioritized actions for security and IT teams:

  • Update the WP Meteor Website Speed Optimization Addon to a version beyond 3.4.18 as soon as a patch is available.
  • Implement a Content Security Policy (CSP) that restricts script execution to trusted domains to mitigate the impact of stored XSS.
  • Utilize Web Application Firewall (WAF) rules to inspect comment submissions for common JavaScript injection patterns (e.g., <script>, onload, onerror).
  • Review all existing pending comments for suspicious author names if the site allows unauthenticated posting.

Immediate actions

Update plugin to latest version

IT Operations 72h

Mitigations

Enable WAF protections for comment injection

immediate SOC

CVE-2026-96572