CVE-2026-16032

The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated analytics endpoint before storing it and rendering it in an administrative dashboard, allowing unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the affected dashboard page.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-09 06:17

Updated : 2026-08-26 16:31


NVD link : CVE-2026-16032

Mitre link : CVE-2026-16032

CVE.ORG link : CVE-2026-16032


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')