Cross-Site Scripting Vulnerability in Optimole WordPress Plugin
CVE-2026-96531
Currently unrated
Key Information:
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-96531?
The Optimole WordPress plugin versions prior to 4.2.13 has a security flaw that allows users with the Author role or higher to insert unescaped event-handler attributes into the video-player block. This occurs because the plugin fails to properly sanitize these attributes prior to rendering. As a result, when other users, including administrators, view the affected content, malicious scripts can be executed in their browsers, posing significant security risks.
Affected Version(s)
Optimole 4.0.0 < 4.2.13
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.