Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-16032

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published Aug 09, 2026
Vendor unknown

Description

The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated analytics endpoint before storing it and rendering it in an administrative dashboard, allowing unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the affected dashboard page.

References