🔐 CVE Alert

CVE-2026-5226

MEDIUM 6.1

Optimole <= 4.2.3 - Reflected Cross-Site Scripting via Page Profiler URL

CVSS Score
6.1
EPSS Score
0.1%
EPSS Percentile
27th

The Optimole – Optimize Images in Real Time plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL paths in versions up to, and including, 4.2.3 This is due to insufficient output escaping on user-supplied URL paths in the get_current_url() function, which are inserted into JavaScript code via str_replace() without proper JavaScript context escaping in the replace_content() function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CWE CWE-79
Vendor optimole
Product optimole – optimize images in real time
Published Apr 11, 2026
Last Updated Apr 13, 2026
Stay Ahead of the Next One

Get instant alerts for optimole optimole – optimize images in real time

Be the first to know when new medium vulnerabilities affecting optimole optimole – optimize images in real time are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

optimole / Optimole – Optimize Images in Real Time
0 ≤ 4.2.3

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/112cea93-fa4b-4692-8c8b-e74255f61939?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/optimole-wp/trunk/inc/manager.php#L459 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/optimole-wp/tags/4.2.1/inc/manager.php#L459 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/optimole-wp/trunk/inc/manager.php#L542 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/optimole-wp/tags/4.2.1/inc/manager.php#L542 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/optimole-wp/trunk/inc/admin.php#L1012 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/optimole-wp/tags/4.2.1/inc/admin.php#L1012 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3498040/optimole-wp/trunk/inc/manager.php plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?old_path=%2Foptimole-wp/tags/4.2.3&new_path=%2Foptimole-wp/tags/4.2.4

Credits

Ali Cem Havare Sencer Kılıç Cesi De Taranto