Authentication Bypass Vulnerability in Optima Express IDX Plugin
CVE-2026-96897
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 27 September 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-96897?
The Optima Express IDX plugin for WordPress prior to version 8.7.6 has a serious issue where it fails to implement authorization checks for certain AJAX actions accessible to users who are not logged in. This could allow unauthorized attackers to create an account with fixed author-role privileges and change its application password on any connected WordPress installation, potentially compromising the security of the site.
Affected Version(s)
Optima Express IDX 8.5.0 < 8.7.6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.