CVE-2026-1843Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Super Page Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Activity Log in all versions up to, and including, 5.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-14: 3Technical Details · 2026-02-14: 302-14
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1843 Stored XSS Vulnerability in Super Page Cache WordPress Plugin Before 5.2.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1843

    Post summary

    The text discloses a stored XSS vulnerability in the Super Page Cache WordPress plugin affecting versions prior to 5.2.2, but offers no PoC, exploit, or patch information.

    0000030
    4.0K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    ⚠️ HIGH-severity XSS flaw in optimole Super Page Cache plugin threatens all WordPress sites! Unauthenticated attackers can inject malicious scripts — update & audit now. https://radar.offseq.com/threat/cve-2026-1843-cwe-79-improper-neutralization-of-in-da8cc8a7 #OffSeq #WordPr... https://t.co/zzQ5R42ZdZ

    Post summary

    A high‑severity XSS vulnerability in the optimole Super Page Cache WordPress plugin has been disclosed, allowing unauthenticated script injection on all sites; no PoC, exploit, or patch details are included in the notice.

    0000041
    268 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1843 The Super Page Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Activity Log in all versions up to, and including, 5.2.2 due to insuffici… https://www.cve.org/CVERecord?id=CVE-2026-1843

    Post summary

    The text announces that the Super Page Cache WordPress plugin is vulnerable to stored XSS in the activity log for versions up to 5.2.2, with no PoC, exploit, patch, or active exploitation details provided.

    00000438
    56.5K followersView on X

Explore more