---
id: CVE-2026-96572
title: >-
  The WP Meteor Website Speed Optimization Addon plugin for WordPress is
  vulnerable to Stored Cross-Site Scripting via Comment Author Name in all
  versions up to, and including, 3.4.18 due to insufficient input sanitization
  and output escap…
summary: >-
  The WP Meteor Website Speed Optimization Addon plugin for WordPress is
  vulnerable to Stored Cross-Site Scripting via Comment Author Name in all
  versions up to, and including, 3.4.18 due to insufficient input sanitization
  and output escap…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
published: '2026-10-10'
updated: '2026-10-10'
sourceUpdated: '2026-10-10T07:16:42.487'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-96572'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-meteor/tags/3.4.18/blocker/FirstInteraction/UltimateReorder.php#L169
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-meteor/tags/3.4.18/blocker/FirstInteraction/UltimateReorder.php#L178
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-meteor/tags/3.4.18/frontend/Rewrite.php#L41
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-meteor/tags/3.4.18/frontend/Rewrite.php#L93
    label: security@wordfence.com
  - url: 'https://plugins.trac.wordpress.org/changeset/3726637'
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset/3726637/wp-meteor/trunk/blocker/FirstInteraction/UltimateReorder.php
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/f54e358c-3bdf-426a-854a-d1bc8ff19afd?source=cve
    label: security@wordfence.com
tags:
  - nvd
ingestedAt: '2026-10-10T07:26:21.927Z'
---

## Overview

The WP Meteor Website Speed Optimization Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 3.4.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is delivered via the comment author name field, which must clear WordPress's comment moderation workflow before being displayed, though this represents a display prerequisite rather than any sanitization control.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
