CVE-2026-96578
Received Received - Intake

Stored XSS in GSpeech TTS WordPress Plugin

Vulnerability report for CVE-2026-96578, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: Wordfence

Description

The GSpeech TTS – WordPress Text To Speech Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.22.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This mXSS-style transform bypasses WordPress comment kses sanitization because the payload is stored using only kses-allowed tags and attributes; the malicious event handlers and style fragments become active only when the plugin's output-buffer callback rewrites the rendered HTML at request time.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
gspeech tts_wordpress_text_to_speech_plugin to 3.22.0 (inc)
gspeech wordpress_text_to_speech_plugin to 3.22.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Stored Cross-Site Scripting (XSS) flaw in the GSpeech TTS WordPress plugin up to version 3.22.0. It allows unauthenticated attackers to inject malicious scripts into comment content due to insufficient input sanitization and output escaping. The injected scripts execute when users view affected pages because the plugin's output processing activates hidden malicious event handlers and style fragments.

Detection Guidance

This vulnerability is specific to the GSpeech TTS WordPress plugin and requires checking for malicious scripts in WordPress comments. Inspect WordPress database tables like wp_comments for unusual content. Use WordPress admin panel to review comments or run SQL queries to search for script tags in comment content.

Impact Analysis

Unauthenticated attackers could inject malicious scripts into WordPress comments. When users access pages with these comments, the scripts execute, potentially stealing user data, session cookies, or performing actions on their behalf. This could lead to account takeovers or unauthorized actions on the website.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating GDPR's data protection principles or HIPAA's security requirements for protected health information. Organizations using this plugin may face compliance violations, fines, or legal consequences if exploited.

Mitigation Strategies

Immediately update the GSpeech TTS plugin to the latest version if available. If no update exists, consider disabling the plugin temporarily. Review and remove any suspicious comments containing scripts. Implement additional WordPress security measures like stricter comment sanitization rules.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-96578. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart