PatchSiren

Web Vitals Tracking CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Web Vitals Tracking CVE published 2026-10-11

CVE-2026-87760

The Web Vitals Tracking WordPress plugin through 5.4.2 does not validate or escape performance measurements submitted by unauthenticated visitors before storing them and outputting them in a script context on an administrative page, allowing unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This vulnerability affects administrators of WordPress installations [truncated]