<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>WP Meteor - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/wp-meteor/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 07:53:02 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/wp-meteor/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored Cross-Site Scripting in WP Meteor Website Speed Optimization Addon</title><link>https://feed.craftedsignal.io/briefs/2026-10-wp-meteor-xss/</link><pubDate>Sat, 10 Oct 2026 07:53:02 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-wp-meteor-xss/</guid><description>The WP Meteor Website Speed Optimization Addon for WordPress versions 3.4.18 and earlier contains a Stored XSS vulnerability allowing unauthenticated attackers to inject malicious scripts via the comment author name field.</description><content:encoded><![CDATA[<p>The WP Meteor Website Speed Optimization Addon plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability impacting all versions up to and including 3.4.18. The flaw arises from insufficient input sanitization and output escaping within the comment author name field. An unauthenticated attacker can supply a crafted payload containing malicious JavaScript as the comment author name. While the comment must bypass the site's moderation workflow to be displayed, the application fails to safely process the input, resulting in the script executing in the browser of any user who views the page where the comment is rendered. This vulnerability presents a high risk for account takeover, session hijacking, or site redirection when administrators or authenticated users interact with the infected comments section.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of the victim's browser session. Depending on the privileges of the user viewing the compromised page, this can lead to administrative account takeover, unauthorized modification of site content, or the injection of further malicious redirects and phishing content. The impact is significant for site integrity and user security, as it affects the frontend display of comments across the WordPress installation.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security and IT teams:</p>
<ul>
<li>Update the WP Meteor Website Speed Optimization Addon to a version beyond 3.4.18 as soon as a patch is available.</li>
<li>Implement a Content Security Policy (CSP) that restricts script execution to trusted domains to mitigate the impact of stored XSS.</li>
<li>Utilize Web Application Firewall (WAF) rules to inspect comment submissions for common JavaScript injection patterns (e.g., &lt;script&gt;, onload, onerror).</li>
<li>Review all existing pending comments for suspicious author names if the site allows unauthenticated posting.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>xss</category><category>web-vulnerability</category><category>wordpress</category><category>cve-2026-96572</category></item></channel></rss>