🔐 CVE Alert

CVE-2026-87760

UNKNOWN 0.0

Web Vitals Tracking <= 5.4.2 - Unauthenticated Stored XSS via Tracking Beacon Metric Name

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Web Vitals Tracking WordPress plugin through 5.4.2 does not validate or escape performance measurements submitted by unauthenticated visitors before storing them and outputting them in a script context on an administrative page, allowing unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators.

Vendor unknown
Product web vitals tracking
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for unknown web vitals tracking

Be the first to know when new unknown vulnerabilities affecting unknown web vitals tracking are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / Web Vitals Tracking
0 ≤ 5.4.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/c6250c43-42c5-4c76-9eb9-2b35ba461e8c/

Credits

Pablo González Pérez Francisco José Ramírez Vicente and Iñigo Sánchez Enciso WPScan