PT-2026-78256 · WordPress · Speed Optimizer

·

CVE-2026-15421

·

Published

2026-08-19

·

Updated

2026-08-20

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Speed Optimizer versions prior to 7.8.1
Description Insufficient input sanitization and output escaping allow authenticated attackers with contributor-level access and above to perform Stored Cross-Site Scripting. This occurs via image tag attributes, enabling the injection of arbitrary web scripts into pages that execute when accessed by other users. This issue is only exploitable if the Lazy Load Media option is enabled in the plugin settings.
Recommendations Update to a version newer than 7.8.0. Disable the Lazy Load Media option in the plugin settings as a temporary mitigation measure.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15421

Affected Products

Speed Optimizer