AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16032

MEDIUM · CVSS 6.1 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-09 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The LWS Optimize WordPress plugin prior to version 4.1.2 is vulnerable due to inadequate input sanitization on an unauthenticated analytics endpoint, enabling attackers to inject malicious scripts. This could lead to cross-site scripting (XSS) attacks, compromising the security of the administrative dashboard when viewed by an administrator. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation risks.

CVE
CVE-2026-16032
Severity
MEDIUM
CVSS
6.1
EPSS
0.16%
WordPress

Original NVD Description

The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated analytics endpoint before storing it and rendering it in an administrative dashboard, allowing unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the affected dashboard page.