CyberRota Analysis
AI-GeneratedThe vulnerability allows unauthenticated cross-site scripting (XSS) in Core Web Vitals & PageSpeed Booster versions up to 1.0.31, potentially enabling attackers to execute arbitrary scripts in the context of a user's session. This could lead to data theft, session hijacking, or defacement of web pages. Organizations using these affected versions should prioritize remediation to mitigate the risk of exploitation.
CVE
CVE-2026-95528
Severity
HIGH
CVSS
7.1
EPSS
0.18%
Original NVD Description
Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions.