Review
Web Vitals Tracking
CVE published 2026-10-11
CVE-2026-87760
The Web Vitals Tracking WordPress plugin through 5.4.2 does not validate or escape performance measurements submitted by unauthenticated visitors before storing them and outputting them in a script context on an administrative page, allowing unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This vulnerability affects administrators of WordPress installations [truncated]