CVE-2026-87760
Received Received - Intake

Web Vitals Tracking Plugin Stored XSS Vulnerability

Vulnerability report for CVE-2026-87760, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: WPScan

Description

The Web Vitals Tracking WordPress plugin through 5.4.2 does not validate or escape performance measurements submitted by unauthenticated visitors before storing them and outputting them in a script context on an administrative page, allowing unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Web Vitals Tracking 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unauthenticated stored Cross-Site Scripting (XSS) flaw in the Web Vitals Tracking WordPress plugin up to version 5.4.2. Attackers can submit malicious performance measurements without authentication, which are then stored and displayed in an administrative page without proper validation or escaping. This allows the injection of malicious scripts that execute when administrators view the page.

Detection Guidance

Check if the Web Vitals Tracking WordPress plugin version 5.4.2 or below is installed. Inspect administrative pages for unexpected scripts or unusual performance measurement inputs. Look for unauthenticated POST requests to /wp-admin/admin-ajax.php with performance data payloads.

Impact Analysis

If you are an administrator using the vulnerable plugin, attackers could inject malicious scripts that execute when you view the affected administrative page. This could lead to unauthorized actions on your behalf, theft of session cookies, or other malicious activities depending on the injected script.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR (data protection) or HIPAA (health information privacy). If attackers gain access to personal or health data through the injected scripts, it could result in non-compliance and potential legal consequences.

Mitigation Strategies

Immediately update the Web Vitals Tracking plugin to the latest version if available. If no update exists, consider disabling or removing the plugin until a patch is released. Monitor administrative pages for suspicious activity or unauthorized script execution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87760. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart