CyberRota Analysis
AI-GeneratedThe LWS Optimize WordPress plugin prior to version 4.1.2 is vulnerable due to inadequate input sanitization on an unauthenticated analytics endpoint, enabling attackers to inject malicious scripts. This could lead to cross-site scripting (XSS) attacks, compromising the security of the administrative dashboard when viewed by an administrator. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation risks.
Original NVD Description
The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated analytics endpoint before storing it and rendering it in an administrative dashboard, allowing unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the affected dashboard page.