PT-2026-8100 · WordPress · Super Page Cache
Angus Girvan
·
Published
2026-02-14
·
Updated
2026-02-14
·
CVE-2026-1843
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Super Page Cache versions prior to 5.2.3
Description
The Super Page Cache plugin for WordPress is susceptible to Stored Cross-Site Scripting through the Activity Log. Insufficient input sanitization and output escaping allows unauthenticated attackers to inject arbitrary web scripts into pages. When a user accesses an injected page, the script will execute.
Recommendations
Update Super Page Cache to version 5.2.3 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Super Page Cache