CVE-2026-16032
Received Received - Intake

LWS Optimize WordPress Plugin Authenticated Stored XSS

Vulnerability report for CVE-2026-16032, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-09

Last updated on: 2026-08-09

Assigner: WPScan

Description

The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated analytics endpoint before storing it and rendering it in an administrative dashboard, allowing unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the affected dashboard page.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-09
Last Modified
2026-08-09
Generated
2026-08-09
AI Q&A
2026-08-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
lws optimize to 4.1.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The LWS Optimize WordPress plugin before version 4.1.2 has an unauthenticated stored cross-site scripting (XSS) vulnerability. It fails to properly escape user input from an unauthenticated analytics endpoint, allowing attackers to inject malicious scripts. These scripts are stored and executed when an administrator views the affected dashboard page.

Detection Guidance

Check if the LWS Optimize WordPress plugin version is below 4.1.2. Inspect network traffic for unauthenticated POST requests to the analytics endpoint (/wp-json/lws-optimize/v1/analytics). Look for stored XSS payloads in the admin dashboard.

Impact Analysis

Unauthenticated attackers can inject malicious scripts into the WordPress dashboard. When an administrator views the dashboard, the injected scripts execute, potentially leading to unauthorized actions, data theft, or further compromise of the WordPress site.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR and HIPAA requirements for data protection and security. Compliance may be compromised if user data is exposed or manipulated due to the injected scripts.

Mitigation Strategies

Update the LWS Optimize plugin to version 4.1.2 or later immediately. If updating is not possible, disable the plugin until a patch is applied. Monitor the admin dashboard for suspicious scripts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16032. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart