Privilege Escalation in Optima Express IDX Plugin for WordPress
CVE-2026-93901

7.3HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
25 September 2026

What is CVE-2026-93901?

The Optima Express IDX plugin for WordPress has a security vulnerability that allows unauthenticated users to escalate their privileges. This flaw arises from the provisionBlogCredentials() function being exposed via the wp_ajax_nopriv_ihf_clear_cache AJAX action without sufficient capability checks, nonce verification, or ownership validation. An attacker can exploit this by registering an account with the hard-coded username optima-express, which then allows them to gain the Author role and associated capabilities. This includes the ability to publish posts, upload files, and edit published posts through the plugin's REST endpoint. To exploit this vulnerability, user registration must be enabled on the target WordPress site.

Affected Version(s)

Optima Express IDX 0 <= 8.7.5

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.