CVE-2026-87760
Web Vitals Tracking <= 5.4.2 - Unauthenticated Stored XSS via Tracking Beacon Metric Name
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Web Vitals Tracking WordPress plugin through 5.4.2 does not validate or escape performance measurements submitted by unauthenticated visitors before storing them and outputting them in a script context on an administrative page, allowing unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators.
| Vendor | unknown |
| Product | web vitals tracking |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown web vitals tracking
Be the first to know when new unknown vulnerabilities affecting unknown web vitals tracking are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / Web Vitals Tracking
0 ≤ 5.4.2
References
Credits
Pablo González Pérez Francisco José Ramírez Vicente and Iñigo Sánchez Enciso WPScan