Reflected Cross-Site Scripting Vulnerability in Optimole Plugin for WordPress
CVE-2026-5226
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 April 2026
What is CVE-2026-5226?
The Optimole β Optimize Images in Real Time plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to insufficient output escaping in the get_current_url() function. This flaw allows unauthenticated attackers to inject arbitrary JavaScript through manipulated URL paths in versions up to 4.2.3. If a user is tricked into clicking a malicious link, the injected scripts may execute in their browser context, posing a risk to user data and website integrity.
Affected Version(s)
Optimole β Optimize Images in Real Time 0 <= 4.2.3