{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/gspeech/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:gspeech:gspeech_tts:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-96578"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GSpeech TTS – WordPress Text To Speech Plugin (\u003c= 3.22.0)"],"_cs_severities":["high"],"_cs_tags":["xss","web-vulnerability","wordpress"],"_cs_type":"advisory","_cs_vendors":["GSpeech"],"content_html":"\u003cp\u003eThe GSpeech TTS - WordPress Text To Speech Plugin is vulnerable to Stored Cross-Site Scripting (XSS) in all versions up to and including 3.22.0. The vulnerability stems from insufficient input sanitization and output escaping within the comment processing logic. Attackers can inject payloads that successfully bypass WordPress comment kses sanitization by utilizing allowed tags and attributes. The payload undergoes a mutation-based cross-site scripting (mXSS) transformation when the plugin's output-buffer callback processes the stored content at render time. This allows malicious JavaScript to execute in the browser of any user viewing the page containing the injected comment. Given that this vulnerability allows unauthenticated access and potential session hijacking or further credential theft, it poses a significant risk to the integrity of WordPress-based web sites.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript within the context of a victim's session. This may lead to unauthorized actions performed on behalf of authenticated administrators, theft of session cookies, or the redirection of users to malicious external sites. All websites running GSpeech TTS version 3.22.0 or earlier are currently exposed to this threat.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the GSpeech TTS - WordPress Text To Speech Plugin to the latest available version beyond 3.22.0 to ensure the patch is applied.\u003c/li\u003e\n\u003cli\u003eAudit existing comments on sites using the affected plugin for suspicious script tags or obfuscated HTML patterns that might indicate exploitation attempts.\u003c/li\u003e\n\u003cli\u003eImplement a Content Security Policy (CSP) that restricts script execution to trusted domains to mitigate the impact of potential XSS vulnerabilities.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T10:23:32Z","date_published":"2026-10-02T10:23:32Z","id":"https://feed.craftedsignal.io/briefs/2026-10-gspeech-xss/","summary":"The GSpeech TTS plugin for WordPress (\u003c= 3.22.0) is vulnerable to Stored Cross-Site Scripting via improper input sanitization and output-buffer manipulation, allowing unauthenticated attackers to execute arbitrary JavaScript.","title":"Stored Cross-Site Scripting in GSpeech TTS Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-gspeech-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - GSpeech","version":"https://jsonfeed.org/version/1.1"}