CVE-2026-16032 PUBLISHED

LWS Optimize < 4.1.2 - Unauthenticated Stored XSS via Real User Monitoring

Assigner: WPScan
Reserved: 17.07.2026 Published: 09.08.2026 Updated: 09.08.2026

The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated analytics endpoint before storing it and rendering it in an administrative dashboard, allowing unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the affected dashboard page.

Product Status

Vendor Unknown
Product LWS Optimize
Versions Default: unaffected
  • affected from 0 to 4.1.2 (excl.)

Credits

  • Artus KG finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE