Junglewise Threat Intelligence

CVE-2026-57783: merkulove Speaker stored XSS in WordPress plugin

CVE-2026-57783 · Severity: medium · CVSS 6.5 · Published 2026-07-13

Vendors: Merkulove.

Executive brief

The Speaker plugin for WordPress, which provides text-to-speech functionality, contains a security flaw that allows users with low-level permissions to inject malicious scripts into the website. If an administrator or visitor views the affected content, these scripts could execute, potentially leading to unauthorized actions, website redirects, or the theft of sensitive session information. As of the latest report, no official patch has been released to address this issue.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the merkulove Speaker plugin for WordPress through version 4.1.13. The flaw stems from improper neutralization of user-supplied input during web page generation, allowing an attacker with 'Contributor' level privileges or higher to inject malicious scripts into the database. These scripts are subsequently executed in the browser of any user (including administrators) who views the compromised content. The attack requires minimal user interaction (viewing the page) and has a CVSS base score of 6.5. No official patch is currently available.

Affected products

  • merkulove Speaker <= 4.1.13

Timeline

  • 2026-02-06: disclosed: Reported by w41bu1
  • 2026-07-02: advisory: Initial advisory published by Patchstack
  • 2026-07-13: advisory: CVE published to NVD dataset

References