PT-2026-78256 · WordPress · Speed Optimizer
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Speed Optimizer versions prior to 7.8.1
Description
Insufficient input sanitization and output escaping allow authenticated attackers with contributor-level access and above to perform Stored Cross-Site Scripting. This occurs via image tag attributes, enabling the injection of arbitrary web scripts into pages that execute when accessed by other users. This issue is only exploitable if the Lazy Load Media option is enabled in the plugin settings.
Recommendations
Update to a version newer than 7.8.0.
Disable the Lazy Load Media option in the plugin settings as a temporary mitigation measure.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Speed Optimizer