Privilege Escalation in Optima Express IDX Plugin for WordPress
CVE-2026-93901
What is CVE-2026-93901?
The Optima Express IDX plugin for WordPress has a security vulnerability that allows unauthenticated users to escalate their privileges. This flaw arises from the provisionBlogCredentials() function being exposed via the wp_ajax_nopriv_ihf_clear_cache AJAX action without sufficient capability checks, nonce verification, or ownership validation. An attacker can exploit this by registering an account with the hard-coded username optima-express, which then allows them to gain the Author role and associated capabilities. This includes the ability to publish posts, upload files, and edit published posts through the plugin's REST endpoint. To exploit this vulnerability, user registration must be enabled on the target WordPress site.
Affected Version(s)
Optima Express IDX 0 <= 8.7.5