CPE
The GSpeech TTS plugin for WordPress (<= 3.22.0) is vulnerable to Stored Cross-Site Scripting via improper input sanitization and output-buffer manipulation, allowing unauthenticated attackers to execute arbitrary JavaScript.